Vulnerability Description
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Notepad-Plus-Plus | Notepad\+\+ | < 7.7 |
| Scintilla | Scintilla | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154706/Notepad-Code-Execution-Denial-Of-SerThird Party AdvisoryVDB Entry
- https://github.com/bi7s/CVE/tree/master/CVE-2019-16294ExploitThird Party Advisory
- https://notepad-plus-plus.org/download/v7.7.htmlRelease NotesVendor Advisory
- https://www.scintilla.org/ScintillaHistory.htmlRelease NotesVendor Advisory
- http://packetstormsecurity.com/files/154706/Notepad-Code-Execution-Denial-Of-SerThird Party AdvisoryVDB Entry
- https://github.com/bi7s/CVE/tree/master/CVE-2019-16294ExploitThird Party Advisory
- https://notepad-plus-plus.org/download/v7.7.htmlRelease NotesVendor Advisory
- https://www.scintilla.org/ScintillaHistory.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2019-16294?
CVE-2019-16294 is a vulnerability with a CVSS score of 7.8 (HIGH). SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
How severe is CVE-2019-16294?
CVE-2019-16294 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16294?
Check the references section above for vendor advisories and patch information. Affected products include: Notepad-Plus-Plus Notepad\+\+, Scintilla Scintilla.