New Notepad update fixes Vault 7 privacy vulnerabilities

2 minute read

Home » News » New Notepad update fixes Vault 7 privacy vulnerabilities

Notepad++ is one of the most popular free source text editors for its ease of use. Supporting several languages, it runs in the MS Windows ecosystem under the GPL License and uses the Win32 API and STL. That means Notepad++ has a higher execution speed and smaller file size. Security-wise, the application was among the vulnerable software programs allegedly targeted by the CIA as part of its massive surveillance program.

Developers of Notepad++ have consequently rolled out version 7.3.3 of the program to fix the vulnerability found in the Vault 7 files leaked by Wikileaks. The files contained classified documents belonging to the CIA. More specifically, Vault 7 comprised a list of popular software programs being targeted by the intelligence agency.

In addition to Notepad++, targeted programs include Google Chrome, VLC Media Player, Firefox, Opera, Kaspersky TDSS Killer, Thunderbird, LibreOffice, and Skype. While it remains unclear when the other programs would get their respective patches, the Notepad++ 7.3.3 patch is now available.

Notepad++ Patch notes

The release notes:

  • Fix CIA Hacking Notepad++ issue (https://wikileaks.org/ciav7p1/cms/page_26968090.html).
  • Patch mouse wheel to task list scroll crash bug.
  • Fix flickering issue while switching back after modifying or deleting a document from outside.
  • Support Motorola S-Record, Intel and Tektronix extended hex file formats.
  • Improve multi-line tab: maintaining the selected tab position.
  • Fix add char into word char list bug.
  • Add Shift+Enter in Find dialog for searching in the opposite direction.
  • Fix a regression that delimiter settings is not retained correctly.
  • Add clear command button in shortcut mapper.
  • Enhancement: file extension supported in Load/Save Session dialog if a session file extension is set.

The hijacked DLL refers to scilexer.dll on an infected computer. The CIA allegedly built a modified scilexer.dll to replace the genuine DLL file once Notepad++ is launched. It prevents the user from detecting the data collection process while it runs in the background.

The new update works to check the certificate validation in scilexer.dll before loading it. Otherwise, Notepad++ will fail to launch. You can download the latest patch from the Notepad++ website.

RELATED STORIES YOU NEED TO CHECK OUT:

Discussions

Next up

How to fix the ETD Control Center not responding error in Windows

Matthew Adams By: Matthew Adams
3 minute read

The ETD Control Center is a Miroelectronics program that’s required for ELAN Smart-Pads. The ELAN Smart-Pads are touchpads that some laptops include just below their […]

Continue Reading

5 of the best font management software for Windows 10

Matthew Adams By: Matthew Adams
5 minute read

Font manager software enables you to organize large font collections more efficiently. The best font manager programs include options and tools for activating and deactivating […]

Continue Reading

Best sound & voice recording apps for Windows 10

Radu Tyrsina By: Radu Tyrsina
2 minute read

I remember that among the first things that I did when I got my first computer was to play around with the sound recorder function. […]

Continue Reading