Notepad++ 8.9.6.1 fixes two security vulnerabilities

Another quick update just days after the release of Notepad++ 8.9.6.

Just days after the release of Notepad++ 8.9.6, developer Don Ho has pushed a follow-up update to version 8.9.6.1 that addresses two security vulnerabilities and resolves a crash bug. Users are encouraged to update promptly given the security nature of the fixes. Notepad++ is free and open source, available for Windows.

What's new

The update closes two code-execution vulnerabilities and patches one crash:

  • Arbitrary code execution was possible via a maliciously crafted config.xml file. An attacker could exploit this to run arbitrary code on the victim's machine if they could get a tampered configuration file loaded by Notepad++.
  • A separate arbitrary code execution path existed through the shortcuts.xml file, exploitable under similar conditions.
  • Notepad++ could be crashed by feeding it malformed COPYDATASTRUCT data, a Windows inter-process communication structure. This has now been patched.

Background for Notepad++

Notepad++ is one of the most widely used free source code and text editors on Windows, with millions of daily users across development, IT, and general productivity workflows.

Find the official release notes here.

Review and download on UpdateStar.

Download from the vendor's site.

about author