Junglewise Threat Intelligence

CVE-2026-38972: Rizonesoft Notepad3 DLL search-order hijacking in About dialog

CVE-2026-38972 · Severity: info · CVSS 7.8 · Published 2026-07-02

Executive brief

Notepad3, a popular text editor, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. By placing a malicious file in the same folder as the application, an attacker can trick the program into running unauthorized code when a user opens the 'About' dialog. This could lead to the theft of sensitive data or full system compromise depending on the user's permissions.

Technical details

A DLL search-order hijacking vulnerability exists in Notepad3 (up to version 6.25.822.1) within the 'About' dialog implementation in src/Notepad3.c. The application calls LoadLibrary() with the bare filename 'MSFTEDIT.DLL' instead of using an absolute path or secure loading flags. A local attacker can exploit this by placing a malicious DLL of the same name in the application's directory or another directory in the system's search order. When a user triggers the About dialog (e.g., via Shift+F1), the malicious DLL is loaded and executed in the context of the current user. The issue was addressed in March 2026 by transitioning to secure library loading practices.

Affected products

  • Rizonesoft Notepad3 Through 6.25.822.1

Timeline

  • 2026-03-23: disclosed: Issue reported on GitHub by user quart27219
  • 2026-03-23: patched: Fix merged in Pull Request #5606
  • 2026-07-02: advisory: CVE-2026-38972 published to NVD

References