CVE-2025-49144: A Silent Shortcut to SYSTEM Privileges in Notepad++

Red | Attack Report
Download PDF

A newly disclosed vulnerability, CVE-2025-49144, affects the Notepad++ installer and could allow attackers to gain full control of a system. The flaw enables malicious actors to place a harmful file in the same directory as the installer, typically the ‘Downloads’ folder, which can be leveraged during installation to compromise the machine. This issue is slated to be addressed in Notepad++ version 8.8.2, and users are strongly advised to update once the fix is released to stay protected.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox