CVE-2022-32168

Source
https://cve.org/CVERecord?id=CVE-2022-32168
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32168.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-32168
Published
2022-09-28T09:00:15Z
Modified
2026-08-12T13:01:10Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
notepad-plus-plus - DLL Hijacking
Details

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

Database specific
{
    "cna_assigner":  "Mend",
    "cwe_ids":  [
        "CWE-427"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32168.json"
}
References

Affected packages

Git / github.com/notepad-plus-plus/notepad-plus-plus

Affected ranges

Type
GIT
Repo
https://github.com/notepad-plus-plus/notepad-plus-plus
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:notepad-plus-plus:notepad\\+\\+:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "8.3"
        },
        {
            "fixed":  "8.4.5"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v8.*
v8.3
v8.3.1
v8.3.2
v8.3.3
v8.4
v8.4.1
v8.4.2
v8.4.3
v8.4.4
v8.4.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32168.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "56126566255679402210989258455246417856",
            "length":  9882
        },
        "id":  "CVE-2022-32168-18f1e3b6",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target":  {
            "file":  "PowerEditor/src/Parameters.cpp",
            "function":  "NppParameters::load"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "73934179812655448165055737310699482624",
                "192340424309136113003180334543256688440",
                "19848721058361772429686884547446302264",
                "190923330591832819628245654696928168249",
                "245670349114795025555380685219528994811"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-32168-1ad9f9ef",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea1e9295ebf5886a02f1646a507b6ce3ec698f0d",
        "target":  {
            "file":  "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "156828762122024156172431670660865497337",
                "289976768516006381916454693285740277141",
                "315489414279550385234886527173753352515",
                "330040123989432357509843978171413098250"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-32168-31dcddf2",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target":  {
            "file":  "PowerEditor/src/MISC/Exception/MiniDumper.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "49448552367143298381372695524493696917",
            "length":  2397
        },
        "id":  "CVE-2022-32168-8af2fba3",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea1e9295ebf5886a02f1646a507b6ce3ec698f0d",
        "target":  {
            "file":  "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp",
            "function":  "AboutDlg::run_dlgProc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "152159363464505116515835069211305167594",
            "length":  1707
        },
        "id":  "CVE-2022-32168-bb116b01",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target":  {
            "file":  "PowerEditor/src/MISC/Exception/MiniDumper.cpp",
            "function":  "MiniDumper::writeDump"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "248477528690320277183539524766857091859",
                "16117762653192841860348303873268124393",
                "82498138416130312033565184262729199023",
                "215444973407686749867596856775498582603"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-32168-d0fa637b",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/85d7215d9b3e0d5a8433fc31aec4f2966821051e",
        "target":  {
            "file":  "PowerEditor/src/Parameters.cpp"
        }
    }
]
vanir_signatures_modified
"2026-08-12T13:01:10Z"