CVE-2023-47452: Notepad-Plus-Plus Notepad++

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

Affected products

Published 2023-11-30. Last modified 2026-06-17.