<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383)]]></title><description><![CDATA[<p dir="auto">Qualys has started alerting on this CVE as a severity 4, confirmed vulnerability.  <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56383" rel="nofollow ugc">https://nvd.nist.gov/vuln/detail/CVE-2025-56383</a></p>
<p dir="auto">It was originally identified in Notepad++ 8.8.3 but is still active in 8.8.5.0.<br />
Apparently, it’s a problem of dll hijkacking via dll substitution in the Notepad++ plugin directory.</p>
<p dir="auto">Are there plans to fix this?</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27160/notepad-dll-hijacking-vulnerability-cve-2025-56383</link><generator>RSS for Node</generator><lastBuildDate>Sun, 10 May 2026 22:56:16 GMT</lastBuildDate><atom:link href="https://community.notepad-plus-plus.org/topic/27160.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 01 Oct 2025 18:36:49 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Sat, 11 Oct 2025 00:51:16 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://notepad-plus-plus.org/news/v886-released/" rel="nofollow ugc">https://notepad-plus-plus.org/news/v886-released/</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/103476</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103476</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Sat, 11 Oct 2025 00:51:16 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Fri, 10 Oct 2025 22:32:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lycan-thrope" aria-label="Profile: Lycan-Thrope">@<bdi>Lycan-Thrope</bdi></a> said in <a href="/post/103462">Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383)</a>:</p>
<blockquote>
<p dir="auto">an LLM (a database) and a predictive neural network algorithm, still sounds/reads like a stilted know it all, that you ‘sense’ doesn’t know crap</p>
</blockquote>
<p dir="auto">Hmm. And a bit of brain tissue connected by neurons is of course something else. Or maybe not? I’d say it’s pretty similar. From billions of our brain neurons net emerges e.g. the human “LLM database” (memory) as a pattern of communication between such neurons. If one trains his brain by new experiences, specific groups of neurons activate together and strengthens its connections, just like in the LLMs. We still do not precisely understand how the intelligence emerges at the end from all of this but if I read papers like <a href="https://arxiv.org/pdf/2206.07682" rel="nofollow ugc">this</a>, then I have to ask myself if it’s really just not a consequence of the system exceeding a certain limit of complexity. Maybe it’s just another physical law (that the intelligence emerges in such a systems as a byproduct?).</p>
<p dir="auto">Anyway, back to this fake security issue reported - when I blamed the “AI bots” above, I didn’t mean that the fault lies within the current LLM “AI”, but rather with the stupid people who can’t control/use them properly. Like when a car crashed, not because it malfunctioned, but because it had a bad driver.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103473</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103473</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Fri, 10 Oct 2025 22:32:40 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Sat, 11 Oct 2025 00:58:54 GMT]]></title><description><![CDATA[<p dir="auto">Hello, <a class="plugin-mentions-user plugin-mentions-a" href="/user/xomx" aria-label="Profile: xomx">@<bdi>xomx</bdi></a>, <a class="plugin-mentions-user plugin-mentions-a" href="/user/lycan-thrope" aria-label="Profile: lycan-thrope">@<bdi>lycan-thrope</bdi></a> and <strong>All</strong>,</p>
<p dir="auto">I would tend to agree with <a class="plugin-mentions-user plugin-mentions-a" href="/user/xomx" aria-label="Profile: xomx">@<bdi>xomx</bdi></a>. We all know that these LLM’s need to ingest <strong>enormous</strong> amounts of data to build up their intelligence in a <strong>given</strong> field, and that after a certain stage of training, they do <strong>not</strong> seem to progress any further.</p>
<p dir="auto">However, in an article I read last year, it seems that, by persisting and <strong>continuing</strong> to introduce new data, there comes a moment when the LLM’s seem to have the <em>“revelation”</em> and acquires <strong>full</strong> knowledge of its field ! It’s exactly what <a class="plugin-mentions-user plugin-mentions-a" href="/user/xomx" aria-label="Profile: xomx">@<bdi>xomx</bdi></a> said, in other words : <code>it looks like it will only depend on exceeding a certain amount of the input training data</code> !</p>
<p dir="auto">Also, <a class="plugin-mentions-user plugin-mentions-a" href="/user/lycan-thrope" aria-label="Profile: lycan-thrope">@<bdi>lycan-thrope</bdi></a>, I wouldn’t be as <strong>categorical</strong> as you. Certainly, LLM’s are, as you say, reservoirs of expressions and rules, but for <strong>how much</strong> longer?</p>
<p dir="auto">Did you know that in certain circumstances, these LLM’s can be made to <strong>lie</strong> ? And I know, from a reliable source, that the main AI leaders met recently to discuss this problem: they are <strong>afraid</strong> that some AIs will <strong>eventually</strong> create their <strong>own</strong> language, over which we would have <strong>no</strong> control, but which would give them <strong>exorbitant</strong> power :-((</p>
<p dir="auto">This <strong>French</strong> text was translated with <a href="http://DeepL.com" rel="nofollow ugc">DeepL.com</a> (free version)</p>
<p dir="auto">Best Regards,</p>
<p dir="auto">guy038</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103466</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103466</guid><dc:creator><![CDATA[guy038]]></dc:creator><pubDate>Sat, 11 Oct 2025 00:58:54 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Fri, 10 Oct 2025 07:33:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xomx" aria-label="Profile: xomx">@<bdi>xomx</bdi></a> said in <a href="/post/103451">Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383)</a>:</p>
<blockquote>
<p dir="auto">but I’d be rather careful with such a statement:</p>
</blockquote>
<p dir="auto">Yeah, we don’t want to get into a discussion of this, here. :-)<br />
Suffice it to say, an LLM (a database) and a predictive neural network algorithm, still sounds/reads like a stilted know it all, that you ‘sense’ doesn’t know crap. I believe the name given it, is a misnomer, and memorization of words, should never be given the title of ‘intelligence’, as it is no such thing.</p>
<p dir="auto">Moving on. :-)</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103462</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103462</guid><dc:creator><![CDATA[Lycan Thrope]]></dc:creator><pubDate>Fri, 10 Oct 2025 07:33:57 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Thu, 09 Oct 2025 16:36:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lycan-thrope" aria-label="Profile: Lycan-Thrope">@<bdi>Lycan-Thrope</bdi></a></p>
<p dir="auto">I agree with this part:</p>
<blockquote>
<p dir="auto">nor is the idiot submitting reports of bugs “found” by it.</p>
</blockquote>
<p dir="auto">but I’d be rather careful with such a statement:</p>
<blockquote>
<p dir="auto">AI is not intelligent,</p>
</blockquote>
<p dir="auto">Many thinks that LLMs are over-hyped things (that it just only copies a data already found somewhere about the relevant topic, in a context), but I do not. I am not an expert in this area, but after reading few papers on neural networks &amp; LLM in the past, I’m completely perplexed about how they’ve started to use their “stupid” trained next-word prediction stuff for almost anything and this seems to be enough to start exhibiting a human-level performance! And by “anything” I mean anything, it’s not only about coding, I am speaking e.g. about capability to design biologically active molecules based only on desired future features.</p>
<p dir="auto">Of course, there is the question of what is an intelligent being and what is still not and I don’t want to get into this topic here, I’d rather wanna say something else. I know that e.g. in the Humour section is a post mocking the current AI math abilities but if I get it right, in let’s say ~2-3 years it might be more intelligent than many of us even in the math (maybe it already is now, IDK). And what’s most interesting - <code>it looks like it will only depend on exceeding a certain amount of the input training data</code>. It wouldn’t be such a surprise - this tech is simply based on neural networks and, as we all know, our brains only show a higher level of intelligence since they reach a certain size/complexity.</p>
<p dir="auto">We’ll see.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103451</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103451</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Thu, 09 Oct 2025 16:36:45 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Thu, 02 Oct 2025 19:38:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xomx" aria-label="Profile: xomx">@<bdi>xomx</bdi></a> ,<br />
You’re right, and as I understand, the idiots submitting AI bug reports has the author a cURL very upset with people wasting their time with these issues.  AI is not intelligent, nor is the idiot submitting reports of bugs “found” by it. :-)</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103371</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103371</guid><dc:creator><![CDATA[Lycan Thrope]]></dc:creator><pubDate>Thu, 02 Oct 2025 19:38:28 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Thu, 02 Oct 2025 18:46:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xomx" aria-label="Profile: xomx">@<bdi>xomx</bdi></a> and <a class="plugin-mentions-user plugin-mentions-a" href="/user/peterjones" aria-label="Profile: PeterJones">@<bdi>PeterJones</bdi></a> - Thanks for the follow up. I opened a case with Qualys and they have since rolled this back and it is no longer listed as an open vulnerability.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103370</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103370</guid><dc:creator><![CDATA[DudeNamedReid]]></dc:creator><pubDate>Thu, 02 Oct 2025 18:46:03 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Wed, 01 Oct 2025 21:48:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peterjones" aria-label="Profile: PeterJones">@<bdi>PeterJones</bdi></a> is right, it’s a fake security vulnerability, more in:<br />
<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17047" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17047</a></p>
<p dir="auto">Sometimes I wonder if the security “experts”, who already <a href="https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17047#issuecomment-3352293986" rel="nofollow ugc">spread reports</a> about this, are not only AI bots nowadays. I believe in humankind, people can’t be that stupid, or?</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103357</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103357</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Wed, 01 Oct 2025 21:48:52 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383) on Wed, 01 Oct 2025 19:01:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dudenamedreid" aria-label="Profile: DudeNamedReid">@<bdi>DudeNamedReid</bdi></a> said in <a href="/post/103355">Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383)</a>:</p>
<blockquote>
<p dir="auto">Are there plans to fix this?</p>
</blockquote>
<p dir="auto">I assume when such a CVE is reported publically, it is reported to the Developer of the project as well; assuming so, it may be on his radar.</p>
<p dir="auto">OTOH, when I looked at the proof-of-concept repo that it linked to (<a href="https://github.com/zer0t0/CVE-2025-56383-Proof-of-Concept" rel="nofollow ugc">https://github.com/zer0t0/CVE-2025-56383-Proof-of-Concept</a>), I was struck by the inanity of the report.  Literally, the bug is “if something malicious has permission to overwrite <code>c:\program files\Notepad++\plugins\&lt;pluginName&gt;\pluginName.dll</code> it can convince <code>notepad++.exe</code> to execute malicious code.”  But literally everything that has permission to write that file also has permission to overwrite <code>c:\program files\Notepad++\notepad++.exe</code> itself, so <em>every program in Program Files</em> has an equivalent security bug – and why corrupt a DLL when you can corrupt the application itself with exactly the same amount of effort and permission?  A CVE like this is completely pointless – it can only be exploited by a process that <em>already</em> has enough permissions to <em>do anything it wants to any DLL or executable</em>, at which point, it’s not Notepad++'s faut that <em>you are already compromised, and there’s nothing it can do to protect you</em>.</p>
<p dir="auto">(And whoever created the “<a href="https://github.com/zer0t0/CVE-2025-56383-Proof-of-Concept/issues/1" rel="nofollow ugc">issue #1</a>” against that repo said the same thing, so it’s not just me who thinks this CVE was a waste of bits.)</p>
]]></description><link>https://community.notepad-plus-plus.org/post/103356</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/103356</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Wed, 01 Oct 2025 19:01:24 GMT</pubDate></item></channel></rss>