  {"id":39491,"date":"2026-02-03T14:02:50","date_gmt":"2026-02-03T19:02:50","guid":{"rendered":"https:\/\/www.yorku.ca\/uit\/?p=39491"},"modified":"2026-02-03T14:03:19","modified_gmt":"2026-02-03T19:03:19","slug":"notepad-vulnerability-cve-2025-15556","status":"publish","type":"post","link":"https:\/\/www.yorku.ca\/uit\/2026\/02\/notepad-vulnerability-cve-2025-15556\/","title":{"rendered":"Notepad ++ Vulnerability (CVE-2025-15556)"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<div class=\"WordSection1\">\n<p class=\"MsoNormal\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<div align=\"center\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"725\" style=\"width:544.0pt;background:#E0E0E0;border-collapse:collapse\">\n<tbody>\n<tr>\n<td style=\"border:solid windowtext 1.0pt;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\"><\/td>\n<\/tr>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"600\" style=\"width:450.0pt;background:white;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td style=\"padding:0cm 0cm 0cm 0cm\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:6.75pt 13.5pt 6.75pt 13.5pt\">\n<p class=\"MsoNormal\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><img loading=\"lazy\" decoding=\"async\" width=\"688\" height=\"100\" style=\"width:7.1666in;height:1.0416in\" id=\"Picture_x0020_2\" src=\"https:\/\/www.yorku.ca\/uit\/wp-content\/uploads\/sites\/805\/2026\/02\/image001-1.png\" alt=\"A picture containing text  Description automatically generated\"><\/span><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\" align=\"center\" style=\"text-align:center;page-break-after:avoid\">  <span style=\"font-family:\"IBM Plex Sans\",sans-serif;mso-fareast-language:EN-US\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p class=\"MsoNormal\" align=\"center\" style=\"margin-bottom:12.0pt;text-align:center;line-height:105%\">  <b><span style=\"font-family:\"IBM Plex Sans\",sans-serif\">Information Security Advisory<\/span><\/b><span class=\"xxxxxxxxnormaltextrun\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p><\/o:p><\/span><\/span><\/p>\n<p style=\"background:white\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white\"><br \/>  A recently discovered Notepad++ vulnerability (CVE\u20112025\u201115556) allows attackers to execute arbitrary code by exploiting insecure update integrity verification.<o:p><\/o:p><\/span><\/p>\n<p style=\"background:white\"><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black\">Severity level<\/span><\/b><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:#242424\">&nbsp;<br \/>  <\/span><\/b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black\">CVSS Score: 7.7\/high<br \/>  <b><br \/>  Description<\/b>:<br \/>  <span style=\"background:white\">Notepad++ is a free and open-source source code editor. A vulnerability exists in Notepad++ versions prior to 8.8.9 involving the WinGUp updater, which fails to cryptographically verify downloaded update metadata and installer   files. An attacker who can intercept or redirect update traffic may fraudulently supply a malicious installer that the updater will download and run. This can result in arbitrary code execution with the privileges of the user, potentially compromising the   system. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory.&nbsp;<br \/>  <\/span><b><br \/>  Affected Versions<\/b><\/span><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:#242424\">:<br \/>  <\/span><\/b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white\">All versions prior to 8.8.9.<br \/>  <b><br \/>  Impact:<br \/>  <\/b>Successful exploitation enables attackers to execute arbitrary code potentially leading to compromise of affected systems.<br \/>  <\/span><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black\"><br \/>  Resolution: <br \/>  <\/span><\/b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white\">Update to the version 8.8.9 or later.<\/span><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p><\/o:p><\/span><\/p>\n<p style=\"background:white\"><span class=\"MsoHyperlink\"><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white;text-decoration:none\">Reference:<\/span><\/b><\/span><span class=\"MsoHyperlink\"><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;text-decoration:none\"><o:p><\/o:p><\/span><\/b><\/span><\/p>\n<p class=\"elementtoproof\" style=\"background:white\"><span class=\"MsoHyperlink\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white;text-decoration:none\"><a href=\"https:\/\/notepad-plus-plus.org\/news\/hijacked-incident-info-update\/\"><span style=\"color:black;text-decoration:none\">https:\/\/notepad-plus-plus.org\/news\/hijacked-incident-info-update\/<\/span><\/a><o:p><\/o:p><\/span><\/span><\/p>\n<p class=\"elementtoproof\" style=\"background:white\"><span class=\"MsoHyperlink\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white;text-decoration:none\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-15556\"><span style=\"color:black;text-decoration:none\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-15556<\/span><\/a><o:p><\/o:p><\/span><\/span><\/p>\n<p class=\"elementtoproof\" style=\"background:white\"><span class=\"MsoHyperlink\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white;text-decoration:none\"><a href=\"https:\/\/www.tenable.com\/cve\/CVE-2025-15556\"><span style=\"color:black;text-decoration:none\">https:\/\/www.tenable.com\/cve\/CVE-2025-15556<\/span><\/a><o:p><\/o:p><\/span><\/span><\/p>\n<p class=\"elementtoproof\" style=\"background:white\"><span class=\"MsoHyperlink\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white;text-decoration:none\"><a href=\"https:\/\/www.tenable.com\/blog\/frequently-asked-questions-about-notepad-supply-chain-compromise\"><span style=\"color:black;text-decoration:none\">https:\/\/www.tenable.com\/blog\/frequently-asked-questions-about-notepad-supply-chain-compromise<\/span><\/a><o:p><\/o:p><\/span><\/span><\/p>\n<p class=\"elementtoproof\" style=\"background:white\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p class=\"elementtoproof\" style=\"background:white\"><span style=\"font-family:\"Calibri\",sans-serif;color:black;background:white\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-bottom:12.0pt;line-height:105%\"><span style=\"font-size:10.0pt;line-height:105%;font-family:\"IBM Plex Sans\",sans-serif;color:black;background:white\"><\/p>\n<p>  Information&nbsp;Security<\/span><span style=\"font-family:\"IBM Plex Sans\",sans-serif\">&nbsp;<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><b><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><\/p>\n<p>  Contact <\/span><\/b><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\" style=\"page-break-after:avoid\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\">IT Client Services at  <\/span><a href=\"mailto:askIT@yorku.ca\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><a href=\"mailto:askIT@yorku.ca\" >askIT@yorku.ca<\/a><\/span><\/a><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"> or 416 736 5800  <span style=\"color:#548235\"><o:p><\/o:p><\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:6.75pt 13.5pt 6.75pt 13.5pt\">\n<p class=\"MsoNormal\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<p class=\"MsoNormal\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"600\" style=\"width:450.0pt;background:white;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"600\" style=\"width:450.0pt;background:#F2F2F2;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:0cm 0cm 0cm 0cm\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" style=\"width:100.0%;border-collapse:collapse\">\n<tbody>\n<tr>\n<td width=\"100%\" style=\"width:100.0%;padding:6.75pt 13.5pt 6.75pt 13.5pt\">\n<p class=\"MsoNormal\"><a href=\"https:\/\/www.yorku.ca\/about\/privacy-legal\/\" target=\"_blank\"><span lang=\"EN-US\" style=\"font-size:10.0pt;font-family:\"IBM Plex Sans\",sans-serif\">PRIVACY POLICY<\/span><\/a><span lang=\"EN-US\" style=\"font-size:10.0pt;font-family:\"IBM Plex Sans\",sans-serif\">&nbsp;|&nbsp;<\/span><a href=\"https:\/\/www.yorku.ca\" target=\"_blank\"><span lang=\"EN-US\" style=\"font-size:10.0pt;font-family:\"IBM Plex Sans\",sans-serif\">VISIT   WWW.YORKU.CA<\/span><\/a><span style=\"font-size:10.0pt;font-family:\"IBM Plex Sans\",sans-serif;color:#505050\"><br \/>  This email was sent by: <b>¿ì²¥ÊÓÆµ, 4700 Keele Street, Toronto, Ontario M3J 1P3<\/b>  <\/span><span style=\"font-size:10.0pt;font-family:\"IBM Plex Sans\",sans-serif\"><o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:10.0pt;font-family:\"IBM Plex Sans\",sans-serif;color:#505050\">This email is viewed best in Microsoft Outlook for web&nbsp;<\/span><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p><\/o:p><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p class=\"MsoNormal\"><span style=\"font-family:\"IBM Plex Sans\",sans-serif\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:11.0pt\"><o:p>&nbsp;<\/o:p><\/span><\/p><\/div>\n<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; Information Security Advisory A recently discovered Notepad++ vulnerability (CVE\u20112025\u201115556) allows attackers to execute arbitrary code by exploiting insecure update integrity verification. Severity level&nbsp; CVSS Score: 7.7\/high Description: Notepad++ is a free and open-source source code editor. A vulnerability exists in Notepad++ versions prior to 8.8.9 involving the WinGUp updater, which fails to cryptographically [&hellip;]<\/p>\n","protected":false},"author":212,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","footnotes":""},"categories":[29],"tags":[],"class_list":["post-39491","post","type-post","status-publish","format-standard","hentry","category-news"],"taxonomy_info":{"category":[{"value":29,"label":"News"}]},"featured_image_src_large":false,"author_info":{"display_name":"aalaily","author_link":"https:\/\/www.yorku.ca\/uit\/author\/aalaily\/"},"comment_info":"","category_info":[{"term_id":29,"name":"News","slug":"news","term_group":0,"term_taxonomy_id":3,"taxonomy":"category","description":"","parent":0,"count":485,"filter":"raw","cat_ID":29,"category_count":485,"category_description":"","cat_name":"News","category_nicename":"news","category_parent":0}],"tag_info":false,"_links":{"self":[{"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/posts\/39491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/users\/212"}],"replies":[{"embeddable":true,"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/comments?post=39491"}],"version-history":[{"count":0,"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/posts\/39491\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/media?parent=39491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/categories?post=39491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.yorku.ca\/uit\/wp-json\/wp\/v2\/tags?post=39491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}