Impact
A flaw in the updater and signature verification path of Notepad++ between versions 8.9.7 and earlier allows a modified GUP.exe file to be accepted when its embedded certificate data is still present, despite the Authenticode digest being invalid. An attacker who can replace or inject the updater‑related file can cause Notepad++ to launch attacker‑modified code when the user triggers an update. The vulnerability does not enable remote code execution on its own; it merely permits execution of code that the attacker has already supplied.
Affected Systems
The affected vendor is Notepad++ with the product Notepad++. Affected versions are 8.9.7; the issue is resolved in version 8.9.8. All other releases are not impacted.
Risk and Exploitability
The CVSS score of 7.3 reflects a moderate to high severity risk. EPSS data is not available, so current exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA KEV. Exploitation would require the attacker to first get access to the updater files—either by tampering with a trusted update source or by acting as a local threat actor with write permissions—after which the modified updater can be executed. While the flaw alone does not confer remote code execution, it can be a precursor for attackers who have already compromised the local system or have intercepted update distribution.
OpenCVE Enrichment