CVE-2022-32168

Source
https://cve.org/CVERecord?id=CVE-2022-32168
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32168.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-32168
Published
2022-09-28T09:00:15.327Z
Modified
2026-08-12T13:01:10.594751Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
notepad-plus-plus - DLL Hijacking
Details

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

Database specific
{
    "cwe_ids": [
        "CWE-427"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32168.json",
    "cna_assigner": "Mend"
}
References

Affected packages

Git / github.com/notepad-plus-plus/notepad-plus-plus

Affected ranges

Type
GIT
Repo
https://github.com/notepad-plus-plus/notepad-plus-plus
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:notepad-plus-plus:notepad\\+\\+:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.3"
        },
        {
            "fixed": "8.4.5"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v8.*
v8.3
v8.3.1
v8.3.2
v8.3.3
v8.4
v8.4.1
v8.4.2
v8.4.3
v8.4.4
v8.4.5

Database specific

vanir_signatures_modified
"2026-08-12T13:01:10Z"
vanir_signatures
[
    {
        "id": "CVE-2022-32168-18f1e3b6",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 9882.0,
            "function_hash": "56126566255679402210989258455246417856"
        },
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target": {
            "function": "NppParameters::load",
            "file": "PowerEditor/src/Parameters.cpp"
        }
    },
    {
        "id": "CVE-2022-32168-1ad9f9ef",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "73934179812655448165055737310699482624",
                "192340424309136113003180334543256688440",
                "19848721058361772429686884547446302264",
                "190923330591832819628245654696928168249",
                "245670349114795025555380685219528994811"
            ]
        },
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea1e9295ebf5886a02f1646a507b6ce3ec698f0d",
        "target": {
            "file": "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp"
        }
    },
    {
        "id": "CVE-2022-32168-31dcddf2",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "156828762122024156172431670660865497337",
                "289976768516006381916454693285740277141",
                "315489414279550385234886527173753352515",
                "330040123989432357509843978171413098250"
            ]
        },
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target": {
            "file": "PowerEditor/src/MISC/Exception/MiniDumper.cpp"
        }
    },
    {
        "id": "CVE-2022-32168-8af2fba3",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 2397.0,
            "function_hash": "49448552367143298381372695524493696917"
        },
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea1e9295ebf5886a02f1646a507b6ce3ec698f0d",
        "target": {
            "function": "AboutDlg::run_dlgProc",
            "file": "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp"
        }
    },
    {
        "id": "CVE-2022-32168-bb116b01",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 1707.0,
            "function_hash": "152159363464505116515835069211305167594"
        },
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target": {
            "function": "MiniDumper::writeDump",
            "file": "PowerEditor/src/MISC/Exception/MiniDumper.cpp"
        }
    },
    {
        "id": "CVE-2022-32168-d0fa637b",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "248477528690320277183539524766857091859",
                "16117762653192841860348303873268124393",
                "82498138416130312033565184262729199023",
                "215444973407686749867596856775498582603"
            ]
        },
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target": {
            "file": "PowerEditor/src/Parameters.cpp"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32168.json"