
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-32168 is a DLL hijacking vulnerability affecting Notepad++ versions 8.4.1 and earlier. The vulnerability was discovered and disclosed in September 2022, impacting the text editor's handling of the UxTheme.dll file (NVD, MITRE).
The vulnerability stems from improper DLL loading mechanisms where an attacker can replace the vulnerable UxTheme.dll with a malicious version. The issue received a CVSS v3.1 score of 7.8 (HIGH), indicating significant security impact (NVD).
If successfully exploited, this vulnerability allows attackers to run arbitrary code in the context of Notepad++, potentially leading to unauthorized code execution with the privileges of the application (MITRE).
The vulnerability was addressed by modifying the DLL loading mechanism to use LOADLIBRARYSEARCH_SYSTEM32 flag when loading the UxTheme.dll, ensuring the DLL is loaded only from the system directory (GitHub).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."