
Vulnerability CVE-2025-49144 in Notepad++ Enables Phishing Attack
EndpointSecurity
The vulnerability CVE-2025-49144 in Notepad++ allows for a phishing attack by exploiting the installer to load a malicious regsvr32.exe file. This exploitation enables the deployment of a Trojan horse and elevates privileges to the system level. Technical details include the use of regsvr32.exe to execute malicious code and obtain elevated privileges. The real impact is the possibility for an attacker to gain full control of the system.