Microsoft fixes Notepad flaw that would trick customers into clicking malicious Markdown hyperlinks


Microsoft has mounted a severe safety vulnerability affecting Markdown recordsdata in Notepad. Within the firm’s Tuesday patch notes, Microsoft says a nasty actor may perform a distant code execution assault by tricking customers “into clicking a malicious hyperlink inside a Markdown file opened in Notepad,” as reported earlier by The Register.

Clicking the hyperlink would “launch unverified protocols,” permitting attackers to remotely load and execute malicious recordsdata on a sufferer’s laptop, based on the patch notes. Microsoft says there isn’t any proof of attackers exploiting the Notepad vulnerability (CVE-2026-20841) within the wild, nevertheless it issued a repair for the flaw in its Tuesday patch.

Microsoft initially added assist for Markdown, a plaintext formatting language, to Notepad on Home windows 11 final Might. The transfer contributed to criticism that Microsoft is filling its working system with bloatware, together with by stuffing new options and AI capabilities into apps like Notepad and Paint.

Notepad isn’t the one textual content editor that has confronted safety points not too long ago, because the third-party Notepad++ app disclosed that some customers could have downloaded a malicious replace linked to Chinese language state-sponsored attackers.



Source link

Related articles

Fifth Third Bancorp: Digesting The Comerica Acquisition (NASDAQ:FITB)

This text was written byObserveThe Funding Physician is a monetary author, highlighting European small-caps with a 5-7 yr funding horizon. He strongly believes a portfolio ought to encompass a combination of dividend and...

MSTR Inventory Forecast as Michael Saylor Hints at Bitcoin Purchases

The MSTR inventory worth dropped for 2 consecutive days and ended the week at $120, down sharply from the all-time excessive of $542. This retreat might proceed this week...

Lion Power secures rig to drill Bula Karang-1 nicely offshore Indonesia

(WO) — Lion Power has contracted the SCD-20 rig from Silver Metropolis Drilling to drill the Bula Karang-1 exploration nicely in Indonesia’s East Seram manufacturing sharing contract, marking a key step towards spudding...

Ought to You Shut Down Your Laptop computer or Simply Shut the Lid?

On the finish of a protracted workday, most of us merely snap our laptops shut and stroll away and not using a second thought. It is a senseless behavior that feels environment friendly,...

Gasoline reservoir hit at Russia’s Primorsk, NORSI refinery on fireplace after drone assaults By Reuters

MOSCOW, April 5 (Reuters) - Gasoline leaked at Russia’s Baltic Sea port of Primorsk, whereas NORSI oil refinery caught fireplace following a drone assault, Russian authorities stated on Sunday. Ukraine has stepped...
spot_img

Latest articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

WP2Social Auto Publish Powered By : XYZScripts.com