CyberRota Analysis
AI-GeneratedNotepad++ versions 8.9.7 to 8.9.8 are vulnerable due to a flaw in the updater and signature verification process, allowing an attacker to replace the GUP.exe file with a modified version that retains invalid certificate metadata. This could lead to the execution of attacker-controlled code when users initiate the update process, posing a significant security risk. Users and organizations utilizing affected versions should prioritize upgrading to version 8.9.8 to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user triggers the updater path, but the issue does not provide remote code execution by itself. This issue is fixed in version 8.9.8.