Description
A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitability is said to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-03-22
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution via Uncontrolled Search Path
Action: Immediate Patch
AI Analysis

Impact

A flaw in the library TextShaping.dll of Flos Freeware Notepad2 allows a local user to manipulate the DLL search order, potentially causing the application to load a malicious DLL instead of the intended one. This can lead to arbitrary code execution with the privileges of the user running the application. The vulnerability is classified as a high severity problem because it gives an attacker control over the execution path without any network access. The weakness falls under CWE‑426 (Untrusted Search Path) and CWE‑427 (Uncontrolled Search Path).

Affected Systems

The affected product is Flos Freeware Notepad2, version 4.2.25. No other versions are listed as vulnerable in the available data.

Risk and Exploitability

The CVSS score of 7.3 indicates a high risk to confidentiality, integrity, and availability for the local machine. Exploitation requires a high level of complexity and is considered difficult, and the attack vector is limited to local execution only. Because the vulnerability is not in the CISA KEV catalog and no EPSS score is available, the likelihood of widespread exploitation remains uncertain, but the potential impact for any affected system is significant.

Generated by OpenCVE AI on March 22, 2026 at 14:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with the vendor for an official patch or newer version of Notepad2 that addresses the TextShaping.dll issue.
  • If no patch is available, avoid running Notepad2 on systems where untrusted or unknown files may be accessed, and limit the installation to trusted users only.
  • Consider switching to an alternative text editor that does not expose this flaw.
  • If possible, restrict the DLL directory by using group policy or file system permissions to prevent the application from loading DLLs from non‑trusted locations.

Generated by OpenCVE AI on March 22, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Flos-freeware
Flos-freeware notepad2
CPEs cpe:2.3:a:flos-freeware:notepad2:4.2.25:*:*:*:*:*:*:*
Vendors & Products Flos-freeware
Flos-freeware notepad2

Mon, 23 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Flos Freeware
Flos Freeware notepad2
Vendors & Products Flos Freeware
Flos Freeware notepad2

Sun, 22 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitability is said to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Title Flos Freeware Notepad2 TextShaping.dll uncontrolled search path
Weaknesses CWE-426
CWE-427
References
Metrics cvssV2_0

{'score': 6, 'vector': 'AV:L/AC:H/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7, 'vector': 'CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Flos-freeware Notepad2
Flos Freeware Notepad2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-23T16:39:39.426Z

Reserved: 2026-03-21T16:44:04.131Z

Link: CVE-2026-4546

cve-icon Vulnrichment

Updated: 2026-03-23T16:15:21.646Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-22T14:16:34.383

Modified: 2026-04-30T14:25:11.943

Link: CVE-2026-4546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:46:29Z

Weaknesses