CVE-2025-49144PoC

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-272CWE-276CWE-427

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-02: 2Mentions · 2026-04-16: 1PoC Mentioned / Linked · 2026-02-02: 2PoC Mentioned / Linked · 2026-04-16: 1Technical Details · 2026-04-16: 102-0204-16
Signal classification2 categories
PoC
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-022
PoC2
2026-04-161
Disclosure1
Full discourse3 posts
  • mRr3b00t@UK_Daniel_Card
    PoC

    'Notepad++ holds approximately 1.33% market share in the IDEs and text editors category, making hundreds of thousands of potentially vulnerable installations worldwide.' https://threatprotect.qualys.com/2025/06/25/poc-released-for-notepad-privilege-escalation-vulnerability-cve-2025-49144/

    Post summary

    A proof‑of‑concept for a privilege escalation flaw in Notepad++ (CVE‑2025‑49144) has been released, highlighting potential risk across many installations, but no further exploit details, active exploitation reports, or mitigation information are provided.

    5725589.5K
    119.7K followersView on X
  • mRr3b00t@UK_Daniel_Card
    PoC

    @maxsec @guyrleech the privesc? https://threatprotect.qualys.com/2025/06/25/poc-released-for-notepad-privilege-escalation-vulnerability-cve-2025-49144/ (coz that's different to the update server being pwn3d)

    Post summary

    A Proof of Concept for Notepad privilege escalation (CVE‑2025‑49144) has been released, but no details on active exploitation, patching, or technical specifics are provided.

    10020329
    119.7K followersView on X
  • Bug bounty wizard@bugbountywizard
    Disclosure

    CVE-2025–49144: Privilege Escalation in Notepad++ v8.8.1 Installer and RCE with SYSTEM Privileges by OSINT Team https://osintteam.blog/cve-2025-49144-privilege-escalation-in-notepad-v8-8-1-installer-and-rce-with-system-privileges-c018d79a5f1d #bugbounty #bugbountytips #bugbountytip #CVE202549144

    Post summary

    OSINT Team announces CVE‑2025‑49144, a privilege escalation and system‑level RCE vulnerability in the Notepad++ 8.8.1 installer, with a linked blog post likely containing technical details and potentially a PoC.

    01010584
    1.3K followersView on X

Explore more