Notepad++ developers released fixes for a high-severity vulnerability in the application's installer, tracked as CVE-2025-49144, that can let an authenticated local attacker escalate privileges and execute code as SYSTEM. The issue affects Notepad++ installer versions 8.8.1 and earlier and does not impact the text editor itself; the flaw carries a CVSS 7.3 severity rating, and a public proof-of-concept exploit is available.
The bug can also be exploited in a remote attack chain if a user is tricked into downloading both a vulnerable installer and a malicious executable into the same folder before launching the installer. Defenders are advised to upgrade to Notepad++ 8.8.2 to remediate the issue and review software distribution workflows that may expose users to tampered installer directories.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A CVE record exists for CVE-2025-49144, documenting the Notepad++ installer vulnerability. The flaw enables local authenticated privilege escalation and can lead to SYSTEM-level code execution under certain conditions.
Public proof-of-concept exploit code was made available for CVE-2025-49144. The disclosure increased the practical risk of exploitation of the vulnerable Notepad++ installer.
Notepad++ developers released security updates to fix CVE-2025-49144, a high-severity privilege escalation flaw in the application's installer affecting version 8.8.1 and earlier. Users and administrators were advised to update to Notepad++ 8.8.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.