
A new zero-day has been discovered in the Notepad application and affects users of the Windows. The bug was discovered by security researcher Tavis Ormandy, a member of Google's Project Zero team, who has found other vulnerabilities and threats in the past.
A malicious actor could exploit the zero-day by opening a Windows CMD window from within the Notepad application. According to Ormandy, this is clearly an exploit, as the attacker cannot properly click on dialogs, which means it is not a security flaw. Ormandy has informally dubbed it “Notebad.”.
Microsoft has already been notified of the zero-day vulnerability. No further details have been released at this time, nor on which versions of Windows are affected, as the Google Project team has given Microsoft 90 days to create a patch for the vulnerability.
Ormandy said he was able to create a remote exploit code using the flaw. He said he will publish the code in a blog post once Microsoft releases a patch for the exploit, or once the deadline has passed. The bug will also be fully documented on a publicly available bug tracker.
