A new DLL hijacking vulnerability in Notepad++ could allow attackers to execute arbitrary code on a victim's computer. The vulnerability, tracked as CVE-2025-56383, exists in version 8.8.3 and potentially affects all installed versions of the software, putting millions of users at risk.

The vulnerability allows a local attacker to achieve code execution by placing a malicious DLL file in a location where the application will load it. This type of attack compromises the integrity of the application and can be used to create persistence or privilege escalation on a compromised system.
Notepad++ DLL hijacking: PoC Exploit Released
The vulnerability allows a local attacker to exploit the software's inability to properly verify DLLs loaded at program startup. This means that an attacker could create a malicious DLL with the same name as a legitimate one used by Notepad++. They could then place it in the same directory as the program's executable. When Notepad++ starts, it will load the malicious DLL instead of the legitimate one, allowing malicious code to be executed.
See also: “Weight Poisoning” Attacks on Neural Networks
In the case of Notepad++, the vulnerability can be exploited by targeting DLLs associated with its plugins. According to the PoC exploit, an attacker can replace a plugin file, such as NppExport.dll, located in the Notepad++\plugins\NppExport\ directory, with a specially crafted malicious DLL.
To remain undetected and ensure that the application continues to function normally, the attacker can rename the original DLL file (e.g., to original-NppExport.dll) and have the malicious replacement forward all function calls to it.
This technique, known as proxying, makes the application appear completely normal and functional to the user while the malicious payload runs in the background.

When Notepad++.exe is launched, the application loads the malicious DLL file, leading to the execution of the attacker's code. A successful exploit is indicated by the appearance of a test message box, which confirms that the arbitrary code was executed with the same privileges as the user running Notepad++.
See also: Serious vulnerabilities in GitLab allow installations to be taken down
This vulnerability is particularly dangerous because it does not require user interaction to be exploited. All an attacker needs to do is access the victim's file system to place the malicious library. This can happen through physical access or through other malicious actions that have preceded it, such as installing malware that allows remote access.
Ways of protection
The main threat here is local code execution. An attacker who has already gained initial access to a system can use this flaw to create persistence.
With DLL hijacking, the attacker's code will execute every time the user opens the processor, ensuring that the malware survives system reboots.
While the demonstration was performed on Notepad++ v8.8.3 installed via the official npp.8.8.3.Installer.x64.exe, the underlying issue is generic and has to do with the way the application loads its components , suggesting that any installed version could be vulnerable.
See also: Fortra GoAnywhere: Vulnerability exploited before public disclosure
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Currently, there is no official patch from Notepad++ developers to address CVE-2025-56383. Users are advised to be cautious and ensure that their systems are free from previous infections.
System administrators should consider implementing file integrity monitoring on application directories to detect unauthorized modifications.

Until a patch is released, users should only download Notepad++ from official sources and be wary of any unexpected behavior from the application.
This vulnerability once again highlights the importance of software security and the need to constantly update and patch the applications we use every day. Users must be aware of the latest security developments and take proactive measures to protect their systems from potential threats.
The Notepad++ development team is already working on a fix for the issue and a security update soon. Users are advised to monitor official announcements and apply the update as soon as it is available to secure their systems.
