CVE-2026-38972

Source
https://cve.org/CVERecord?id=CVE-2026-38972
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-38972.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-38972
Published
2026-07-02T00:00:00Z
Modified
2026-07-15T01:49:08.106049846Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user when the About dialog is opened.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/38xxx/CVE-2026-38972.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/rizonesoft/notepad3

Affected ranges

Type
GIT
Repo
https://github.com/rizonesoft/notepad3
Events
Database specific
{
    "cpe": "cpe:2.3:a:rizonesoft:notepad3:*:*:*:*:*:*:*:*",
    "source": [
        "DESCRIPTION",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "Notepad3"
        },
        {
            "fixed": "6.25.822.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.25.822.1"
        }
    ]
}

Affected versions

RC2_5.*
RC2_5.20.218.2
RC2_6.*
RC2_6.24.109.1
RC3_6.*
RC3_6.24.309.1
RC_3.*
RC_3.18.422.952
RC_4.*
RC_4.18.507.981
RC_5.*
RC_5.18.1003.1309
RC_5.18.1106.1432
RC_5.19.528.2228
RC_5.19.726.2515
RC_5.20.218.2
RC_5.20.829.2
RC_5.21.1109.1
RC_5.21.207.1
RC_5.22.1119.1
RC_6.*
RC_6.23.712.1
RELEASE_4.*
RELEASE_4.18.512.992
RELEASE_5.*
RELEASE_5.19.108.1602
RELEASE_5.19.815.2595
RELEASE_5.20.722.1
RELEASE_5.21.1129.1
RELEASE_5.21.227.1
RELEASE_5.21.905.1
RELEASE_6.*
RELEASE_6.23.203.2
RELEASE_6.24.1221.1
RELEASE_6.25.714.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-38972.json"