Notepad++是中国台湾侯今吾(Don Ho)个人开发者的一款开源的纯文本编辑器。 Notepad++ 8.8.9之前版本存在安全漏洞,该漏洞源于使用WinGUp更新器时更新完整性验证不足,可能导致执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | 0 ~ 8.8.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale queries, YARA/Sigma rules, and MITRE ATT&CK mapping. | https://github.com/renat0z3r0/notepadpp-supply-chain-iocs | POC Details |
| 2 | None | https://github.com/George0Papasotiriou/CVE-2025-15556-Notepad-WinGUp-Updater-RCE | POC Details |
No public POC found.
Login to generate AI POCNo comments yet