CVE-2022-32168
Notepad++ vulnerability analysis and mitigation

Overview

CVE-2022-32168 is a DLL hijacking vulnerability affecting Notepad++ versions 8.4.1 and earlier. The vulnerability was discovered and disclosed in September 2022, impacting the text editor's handling of the UxTheme.dll file (NVD, MITRE).

Technical details

The vulnerability stems from improper DLL loading mechanisms where an attacker can replace the vulnerable UxTheme.dll with a malicious version. The issue received a CVSS v3.1 score of 7.8 (HIGH), indicating significant security impact (NVD).

Impact

If successfully exploited, this vulnerability allows attackers to run arbitrary code in the context of Notepad++, potentially leading to unauthorized code execution with the privileges of the application (MITRE).

Mitigation and workarounds

The vulnerability was addressed by modifying the DLL loading mechanism to use LOADLIBRARYSEARCH_SYSTEM32 flag when loading the UxTheme.dll, ensuring the DLL is loaded only from the system directory (GitHub).

Additional resources


SourceThis report was generated using AI

Related Notepad++ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-47452HIGH7.8
  • Notepad++Notepad++
  • cpe:2.3:a:notepad-plus-plus:notepad\+\+
NoYesNov 30, 2023
CVE-2023-6401HIGH7.8
  • Notepad++Notepad++
  • cpe:2.3:a:notepad-plus-plus:notepad\+\+
NoYesNov 30, 2023
CVE-2025-49144HIGH7.3
  • Notepad++Notepad++
  • cpe:2.3:a:notepad-plus-plus:notepad\+\+
NoYesJun 23, 2025
CVE-2023-40166MEDIUM5.5
  • Notepad++Notepad++
  • cpe:2.3:a:notepad-plus-plus:notepad\+\+
NoYesAug 25, 2023
CVE-2023-40164MEDIUM5.5
  • Notepad++Notepad++
  • cpe:2.3:a:notepad-plus-plus:notepad\+\+
NoYesAug 25, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management