21
top 7 comments
sorted by: hot top controversial new old
[-] WaterWaiver@aussie.zone 32 points 6 days ago* (last edited 6 days ago)

Bogus CVE. Spam.

From the PoC:

Replace the original DLL (such as Notepad++\plugins\NppExport\NppExport.dll) with a DLL file with the same name containing malicious code

If you replace parts of a program with malware then you can get malware to run. This is true of all software.

[-] CookieOfFortune@lemmy.world 4 points 6 days ago

Looks like the article was written by AI.

[-] 0_o7@lemmy.dbzer0.com 1 points 6 days ago

If you login to your own account and post "this account is hacked", you've been pwned.

-1337 H4CK3R

[-] TeamAssimilation@infosec.pub 1 points 6 days ago

Bro can I have the exploit please bro? How did you do it?

[-] ChairmanMeow@programming.dev 9 points 6 days ago

One of the NPP maintainers responded with:

Notepad++ & its plugins are installed in "Program Files" directory by default, which means hackers would need admin privileges to replace any plugin. If a hacker gains such privileges, they could also replace all the DLLs in the system32 folder. By the same logic, once Notepad++ is compromised in this way, any applications or executable binary (*.exe & *.dll) on the system could potentially be replaced. Or am I missing somethings?

Which I suppose is true. You could argue it is a way to persist malicious code once you do have access, but it seems unlikely and not that useful. Low severity if anything.

You'd need to have some general attack script that can adjust (or create proxies for) dlls maliciously on the fly, without prior knowledge of which dlls are encountered. Only in that case could the exe maybe detect malicious changes to the dll and stop execution. But a targeted attack using a compromised NPP distribution wouldn't be covered with such a check.

[-] davidagain@lemmy.world 2 points 5 days ago* (last edited 5 days ago)

At first I thought "oh, I wonder if my favourite text editor is affected by a similar bug, and I wonder what actions make it vulnerable.".

Well, of turns out that the action that makes it vulnerable is installing separate malware with admin privileges. I will do my best to avert that danger, but I wouldn't class "third party malware with admin privileges can replace part of this program with its own code" as a serious vulnerability in this software specifically.

What a silly article.

this post was submitted on 30 Sep 2025
21 points (69.1% liked)

cybersecurity

5026 readers
14 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 2 years ago
MODERATORS