CVE-2022-32168

Source
https://cve.org/CVERecord?id=CVE-2022-32168
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32168.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-32168
Published
2022-09-28T09:00:15.327Z
Modified
2026-07-22T02:24:23.651497Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
notepad-plus-plus - DLL Hijacking
Details

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32168.json",
    "cna_assigner": "Mend",
    "cwe_ids": [
        "CWE-427"
    ]
}
References

Affected packages

Git / github.com/notepad-plus-plus/notepad-plus-plus

Affected ranges

Type
GIT
Repo
https://github.com/notepad-plus-plus/notepad-plus-plus
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "8.3"
        },
        {
            "fixed": "8.4.5"
        }
    ],
    "cpe": "cpe:2.3:a:notepad-plus-plus:notepad\\+\\+:*:*:*:*:*:*:*:*"
}

Affected versions

v8.*
v8.3
v8.3.1
v8.3.2
v8.3.3
v8.4
v8.4.1
v8.4.2
v8.4.3
v8.4.4
v8.4.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32168.json"
vanir_signatures_modified
"2026-07-22T02:24:23Z"
vanir_signatures
[
    {
        "target": {
            "file": "PowerEditor/src/Parameters.cpp",
            "function": "NppParameters::load"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2022-32168-18f1e3b6",
        "signature_version": "v1",
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "digest": {
            "function_hash": "56126566255679402210989258455246417856",
            "length": 9882.0
        }
    },
    {
        "target": {
            "file": "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2022-32168-1ad9f9ef",
        "signature_version": "v1",
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea1e9295ebf5886a02f1646a507b6ce3ec698f0d",
        "digest": {
            "line_hashes": [
                "73934179812655448165055737310699482624",
                "192340424309136113003180334543256688440",
                "19848721058361772429686884547446302264",
                "190923330591832819628245654696928168249",
                "245670349114795025555380685219528994811"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "PowerEditor/src/MISC/Exception/MiniDumper.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2022-32168-31dcddf2",
        "signature_version": "v1",
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "digest": {
            "line_hashes": [
                "156828762122024156172431670660865497337",
                "289976768516006381916454693285740277141",
                "315489414279550385234886527173753352515",
                "330040123989432357509843978171413098250"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp",
            "function": "AboutDlg::run_dlgProc"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2022-32168-8af2fba3",
        "signature_version": "v1",
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea1e9295ebf5886a02f1646a507b6ce3ec698f0d",
        "digest": {
            "function_hash": "49448552367143298381372695524493696917",
            "length": 2397.0
        }
    },
    {
        "target": {
            "file": "PowerEditor/src/MISC/Exception/MiniDumper.cpp",
            "function": "MiniDumper::writeDump"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2022-32168-bb116b01",
        "signature_version": "v1",
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "digest": {
            "function_hash": "152159363464505116515835069211305167594",
            "length": 1707.0
        }
    },
    {
        "target": {
            "file": "PowerEditor/src/Parameters.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2022-32168-d0fa637b",
        "signature_version": "v1",
        "source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "digest": {
            "line_hashes": [
                "248477528690320277183539524766857091859",
                "16117762653192841860348303873268124393",
                "82498138416130312033565184262729199023",
                "215444973407686749867596856775498582603"
            ],
            "threshold": 0.9
        }
    }
]