Impact
The flaw resides in the PROPSYS.dll library used by Flos Freeware Notepad2. Because the library does not enforce a secure search path, a local user can place a malicious DLL in a directory that the system prefers during loading. When the application loads the library, it will execute code from the attacker‑supplied DLL, effectively leading to code execution on the victim machine.
Affected Systems
The vulnerability affects Flos Freeware Notepad2 version 4.2.25. No other versions are listed, so systems running that specific release are at risk.
Risk and Exploitability
The CVSS base score of 7.3 indicates high severity. While EPSS data is unavailable and the issue is not listed in CISA's KEV catalog, the local‑only attack surface means an attacker must have physical or administrative access to the target machine. The attack requires write access to search‑path directories and is considered difficult to exploit, but once a malicious DLL is in place, the impact is full code execution.
OpenCVE Enrichment