<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[libcurl.dll and CVE-2023-32001]]></title><description><![CDATA[<p dir="auto">One of our Windows 2019 servers has Notepad++ installed and has been flagged as having a vulnerability, namely CVE-2023-32001 relating to libcurl.dll. I checked the server and the only instance of that file I could find was in “C:\Program Files\Notepad++\updater” and the file version is 7.79.1.0. I just updated Notepad+ to the latest release 8.5.4 to see if the file would be updated but it didn’t. Will that file eventually get updated at some point or is there any issues if I remove it or remove the automatic updater service assuming that is possible?</p>
<p dir="auto">Peter</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/24764/libcurl-dll-and-cve-2023-32001</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 11:43:23 GMT</lastBuildDate><atom:link href="https://community.notepad-plus-plus.org/topic/24764.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 02 Aug 2023 15:40:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to libcurl.dll and CVE-2023-32001 on Mon, 07 Aug 2023 09:51:48 GMT]]></title><description><![CDATA[<p dir="auto">Great, thanks both for your comments.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/88409</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/88409</guid><dc:creator><![CDATA[Peter Fell]]></dc:creator><pubDate>Mon, 07 Aug 2023 09:51:48 GMT</pubDate></item><item><title><![CDATA[Reply to libcurl.dll and CVE-2023-32001 on Thu, 03 Aug 2023 23:47:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter-fell" aria-label="Profile: Peter-Fell">@<bdi>Peter-Fell</bdi></a> said in <a href="/post/88271">libcurl.dll and CVE-2023-32001</a>:</p>
<blockquote>
<p dir="auto">libcurl.dll</p>
</blockquote>
<p dir="auto">In looking at <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32001" rel="nofollow ugc">https://nvd.nist.gov/vuln/detail/CVE-2023-32001</a> the dll is getting flagged because someone feels that the libcurl developers used a common coding practice that could potentially be exploited.</p>
<p dir="auto"><a href="https://hackerone.com/reports/2039870" rel="nofollow ugc">https://hackerone.com/reports/2039870</a> goes into much detail.  It appears the libcurl developers are aware of the issue.</p>
<p dir="auto">If the potential vulnerability bothers you then disable Notpad++'s automatic check for updates and delete or rename libcurl.dll.  It’s only used to check for and download updates to Notepad++. If you then do a “Check for updates” you will get a pop-up about</p>
<pre><code class="language-txt">GUP.exe - System Error
The code execution cannot proceed because libcurl.dll was not found. Reinstalling the program may fix this problem. 
</code></pre>
<p dir="auto">I suspect the odds are low it could be exploited as the attacker would first need to find libcurl.dll and then to have an elevated process use it.  Normally libcurl.dll is only used by GUP.exe which is itself is normally not elevated. I’d need to think about if and when GUP.exe gets elevated. Maybe it does so when it sees that it needs to update the Notepad++.exe files? I suspect though that GUP.exe first downloads the new installer using libcurl.dll as a non-elevated process and then elevates to perform the installation.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/88324</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/88324</guid><dc:creator><![CDATA[mkupper]]></dc:creator><pubDate>Thu, 03 Aug 2023 23:47:02 GMT</pubDate></item><item><title><![CDATA[Reply to libcurl.dll and CVE-2023-32001 on Wed, 02 Aug 2023 16:32:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter-fell" aria-label="Profile: Peter-Fell">@<bdi>Peter-Fell</bdi></a> said in <a href="/post/88271">libcurl.dll and CVE-2023-32001</a>:</p>
<blockquote>
<p dir="auto">Will that file eventually get updated at some point or is there any issues if I remove it or remove the automatic updater service assuming that is possible?</p>
</blockquote>
<p dir="auto">I checked for issues regarding that CVE or searching for “libcurl” in the issues.  It looks like someone <a href="https://github.com/notepad-plus-plus/notepad-plus-plus/issues/13139" rel="nofollow ugc">reported libcurl 7.79.1 here</a> and then was asked to re-report it <a href="https://github.com/notepad-plus-plus/wingup/issues/36" rel="nofollow ugc">in the wingup repo</a>.</p>
<p dir="auto">The developer self-assigned the issue, but may have forgotten about it.  I will ping that issue.</p>
<blockquote>
<p dir="auto">or is there any issues if I remove it or remove the automatic updater service assuming that is possible?</p>
</blockquote>
<p dir="auto">Notepad++ won’t be able to auto-update.  Other than that, no issues that I’m aware of.  So if you’re worried until libcurl gets updated, you can manually delete libcurl.dll and gup.exe from your notepad++ installation.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/88273</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/88273</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Wed, 02 Aug 2023 16:32:23 GMT</pubDate></item></channel></rss>