CVE-2025-49144 | notepad-plus-plus Notepad++ up to 8.8.1 Installer least privilege violation (GHSA-9vx8-v79m-6m24 / EUVD-2025-19601)
A vulnerability was found in notepad-plus-plus Notepad++ up to 8.8.1. It has been classified as critical. Affected is an unknown function of the component Installer. This manipulation causes least privilege violation.
This vulnerability is registered as CVE-2025-49144. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.