CVE-2026-38972
As of 2026-07-02, CVE-2026-38972 is a vulnerability. Threadlinqs Intelligence tracks 0 threats exploiting it.
Last updated: 2026-07-02
Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user when the About dialog is opened.
References
- https://github.com/rizonesoft/Notepad3/pull/5606
- https://github.com/rizonesoft/Notepad3/issues/5605
- https://github.com/rizonesoft/Notepad3
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.