Notepad++ 8.9.8 Offers Security Fixes and Crash Patches

The free and open-source text/code editor that's a staple on millions of Windows PCs, has shipped version 8.9.8.

Notepad++, the free and open-source text/code editor that's a staple on millions of Windows PCs, has shipped version 8.9.8. The update landed doesn't bring flashy new features, it closes off a notable batch of security holes and a couple of crash bugs, worth installing sooner rather than later if you use Notepad++ daily.

What's New in 8.9.8

Security fixes:

  • Fixed a TOCTOU (time-of-check to time-of-use) issue in the Notepad++ Updater (WinGUp)
  • Fixed a session backup path-traversal bug that could allow file deletion outside the backup directory
  • Fixed potential exposure of Windows login credentials (SMB/NTLM) via UNC paths
  • Fixed a shortcuts.xml HMAC bypass reachable through "Run a Macro Multiple Times"
  • Fixed a "Folder as Workspace" target-hijacking issue tied to how the app determines what's "run by system"
  • Fixed an install-path injection risk involving PowerShell
  • Fixed an issue where a lower Integrity Level (IL) process could send WM_COMMAND messages to a higher-IL Notepad++ instance

Stability fixes:

  • Fixed a null pointer bug in the NPPM_SAVESESSION handler that was causing crashes
  • Fixed a stack buffer overflow triggered by overlong session paths

Why It Matters

Several of these fixes close privilege-escalation and credential-leak vectors rather than being routine bug tidying, so this is a recommended update for anyone running Notepad++ in a shared or networked environment.

Download

Grab the update directly from the official site: notepad-plus-plus.org/downloads/v8.9.8

Full release notes: notepad-plus-plus.org/news/v898-released

Track version history and update checks via UpdateStar: notepad.updatestar.com

about author