EXPOSURES › CVE-2025-15556
CVE-2025-15556
HIGH ⌖ ON CISA KEV · EXPLOITEDNotepad++'s WinGUp updater lacks integrity checks, enabling attackers to execute arbitrary code via compromised updates.
Notepad++'s update mechanism via WinGUp is vulnerable to intercepting update traffic, allowing attackers to execute arbitrary code with the privileges of the user. This could lead to a severe security breach.
Shame score — Vulnerability actively exploited, posing a high risk to users' systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.