CyberRota Analysis
AI-GeneratedNotepad++ versions prior to 8.9.8 are vulnerable to a stack buffer overflow in the session saving functionality, which can lead to a denial of service when an excessively long settings directory path is used. This vulnerability arises from unbounded string copying and concatenation, potentially allowing for exploitation in environments where Notepad++ is deployed. Organizations using Notepad++ should prioritize upgrading to version 8.9.8 or later to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDir= into backupPathName[MAX_PATH] with unbounded wcscpy and appends SESSION_BACKUP_EXT with unbounded wcscat. A sufficiently long settings directory causes the backup suffix to exceed the fixed stack buffer when Notepad++ saves the session, and the protected release build terminates through its stack canary, causing denial of service. This issue is fixed in version 8.9.8.