CVE-2025–49144: Notepad++ vulnerability allows full system compromise
Notepad++ v8.8.1被发现存在严重漏洞(CVE-2025-49144),攻击者可利用该漏洞通过操控regsvr32.exe路径获取系统权限。安装程序在当前目录搜索依赖项时未验证文件来源,导致恶意代码执行。该漏洞可能与钓鱼攻击结合使用,增加风险。建议采用绝对路径、验证文件签名等措施防范。
You must login to view this content
You must login to view this content
You must login to view this content
You must login to view this content
You must login to view this content
You must login to view this content
You must login to view this content