Impact
A flaw in the library TextShaping.dll of Flos Freeware Notepad2 allows a local user to manipulate the DLL search order, potentially causing the application to load a malicious DLL instead of the intended one. This can lead to arbitrary code execution with the privileges of the user running the application. The vulnerability is classified as a high severity problem because it gives an attacker control over the execution path without any network access. The weakness falls under CWE‑426 (Untrusted Search Path) and CWE‑427 (Uncontrolled Search Path).
Affected Systems
The affected product is Flos Freeware Notepad2, version 4.2.25. No other versions are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 7.3 indicates a high risk to confidentiality, integrity, and availability for the local machine. Exploitation requires a high level of complexity and is considered difficult, and the attack vector is limited to local execution only. Because the vulnerability is not in the CISA KEV catalog and no EPSS score is available, the likelihood of widespread exploitation remains uncertain, but the potential impact for any affected system is significant.
OpenCVE Enrichment