Article 73GDK Microsoft fixes Notepad flaw that could trick users into clicking malicious Markdown links

Microsoft fixes Notepad flaw that could trick users into clicking malicious Markdown links

by
Emma Roth
from The Verge on (#73GDK)
STK109_WINDOWS_C.jpg?quality=90&strip=all&crop=0,0,100,100

Microsoft has fixed a serious security vulnerability affecting Markdown files in Notepad. In the company's Tuesday patch notes, Microsoft says a bad actor could carry out a remote code execution attack by tricking users "into clicking a malicious link inside a Markdown file opened in Notepad," as reported earlier by The Register.

Clicking the link would "launch unverified protocols," allowing attackers to remotely load and execute malicious files on a victim's computer, according to the patch notes. Microsoft says there isn't any evidence of attackers exploiting the Notepad vulnerability (CVE-2026-20841) in the wild, but it issued a fix for ...

Read the full story at The Verge.

External Content
Source RSS or Atom Feed
Feed Location http://www.theverge.com/rss/index.xml
Feed Title The Verge
Feed Link https://www.theverge.com/
Reply 0 comments