By vendor
Rizonesoft vulnerabilities
Known CVEs affecting Rizonesoft products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-38972HIGH 7.8
Notepad3 versions up to 6.25.822.1 contain a DLL search-order hijacking flaw that allows a local attacker to inject malicious code. When a user opens the About dialog, the application attempts to load a library file (MSFTEDIT.DLL) by name alone, without specifying a full path. An attacker who can write files to the application's directory or to other locations Windows searches for DLLs can plant a malicious version and achieve arbitrary code execution under the user's privileges. This is a classic privilege-escalation and code-execution vector that requires local file-system access but no special user privileges to exploit.