HIGH
Flos Freeware Notepad2 TextShaping.dll uncontrolled search path
Published Mar 22, 2026
7.3
HIGHCVSS 4.0
EPSS 0.21%
Description
A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitability is said to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 4.2.25StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Flos Freeware | Notepad2 | n/a |
|
- 4.2.25
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://drive.google.com/file/d/1w5-ztNIN28mPuidtjlsilKsKKQQNOiIJ/view relatedPermissions Required
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14303 Advisory
- https://vuldb.com/?ctiid.352373 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.352373 vdb-entryThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.774778 third-party-advisoryExploitThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/file/d/1w5-ztNIN28mPuidtjlsilKsKKQQNOiIJ/view | relatedPermissions Required | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14303 | Advisory | |
| https://vuldb.com/?ctiid.352373 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.352373 | vdb-entryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.774778 | third-party-advisoryExploitThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 22, 2026
Updated Mar 23, 2026
Reserved Mar 21, 2026
Link CVE-2026-4546
CISA Vulnrichment
Updated Mar 23, 2026
ENISA EUVD
EUVD-2026-14303 Assigner VulDB
Published Mar 22, 2026
Updated Mar 23, 2026
Exploited since n/a
Link EUVD-2026-14303