A few days ago, Notepad++ got compromised—apparently by a state actor (or a proxy). And now, today, Windows’ built-in Notepad has a fresh CVE. What a life. At this point, what am I supposed to do other than uninstall Windows completely? No real sandboxing, a mountain of legacy…
Windows Notepad App Remote Code Execution Vulnerability
371–380 of 538 posts
Re: Windows Notepad App Remote Code Execution Vulnerability
#372Earlier quoted context omitted.
I extracted out notepad.exe, calc.exe and mspaint.exe from Windows 7. I use them on Windows 11. They work perfectly.
I have the mspaint.exe from the same version too :P. It complains about registry stuff on launch but other than that it works fine. There's no spray can in the modern paint!
I copied out mspaint.exe and some resource files as well were needed.
It runs for me without error.
Re: Windows Notepad App Remote Code Execution Vulnerability
#373Re: Windows Notepad App Remote Code Execution Vulnerability
#374Earlier quoted context omitted.
But... did they add a http server in it? Mail reader?
Rewrote it in Rust
Edit: Fedora has it available as "msedit". What a time to be alive.
Re: Windows Notepad App Remote Code Execution Vulnerability
#375Earlier quoted context omitted.
I extracted out notepad.exe, calc.exe and mspaint.exe from Windows 7. I use them on Windows 11. They work perfectly.
Kind of a weird feeling that in order to get the better Windows 11 experience one requires programs from four operating system versions earlier. Windows 11 also takes a huge amount of time to get working as i intend. I have to remove a lot of 'features' and heavily optimize some processes. It's stable and it works, but i'm getting more and more annoyed by it that upcoming updates sometimes destroy all my effort. Kind…
But some things just don’t run there (properly).
Like Assetto Corsa EVO or SimHub.
Re: Windows Notepad App Remote Code Execution Vulnerability
#376It is to do with link handling: https://msrc.microsoft.com/update-guide/vulnerability/CVE-20... > An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files.
Re: Windows Notepad App Remote Code Execution Vulnerability
#377Earlier quoted context omitted.
I extracted out notepad.exe, calc.exe and mspaint.exe from Windows 7. I use them on Windows 11. They work perfectly.
Kind of a weird feeling that in order to get the better Windows 11 experience one requires programs from four operating system versions earlier. Windows 11 also takes a huge amount of time to get working as i intend. I have to remove a lot of 'features' and heavily optimize some processes. It's stable and it works, but i'm getting more and more annoyed by it that upcoming updates sometimes destroy all my effort. Kind…
The Web versions of Office, err MS 365, err CoPilot App.. (OMG!>!!>) ... aren't so bad to use in a Linux browser either.
Re: Windows Notepad App Remote Code Execution Vulnerability
#378Earlier quoted context omitted.
> Except no, we don't. notepad.exe was DONE SOFTWARE While 8.8 score is embarrassing, by no measure notepad was done software. It couldn't load a large text file for one, its search was barely functional, had funky issues with encoding, etc. Notepad++ is closer to what should be expected from an OS basic text editor
What counts as "large"? I'm pretty sure at some point in my life I'd opened the entirety of Moby Dick in Notepad. Unless you want to look for text in a binary file (which Notepad definitely isn't for) I doubt you'll run into that problem too often. Also, I hope the irony of you citing Notepad++ [1] as what Notepad should aim to be isn't lost on you. My point being, these kinds of vulnerabilities shouldn't exist in a…
Regarding large, I am referring to log files for example. I think the issue was lack of use of memory mapped files, which meant the entire file was loaded to RAM always, often giving the frozen window experience
Re: Windows Notepad App Remote Code Execution Vulnerability
#379Earlier quoted context omitted.
I have the mspaint.exe from the same version too :P. It complains about registry stuff on launch but other than that it works fine. There's no spray can in the modern paint!
I like paint shop pro, I use 4.12.
I try to use Pinta/Paint.Net, but it's not quite as good as I remember psp being. I don't even hate the newer MS Paint... thought I'm only on windows for my work environment and even then.
Aside: I've been using my personal computer more, so I can work on a limited surface with docker and ai agent, then just bring in the components I'm working on when ready. My work environment is really locked down, no wsl, no docker... and it's like working in 2002 to some extent... It's literally easier for me to create stand-alone projects, work on a given feature in complete isolation... AI agent mostly to boilerplate the environment and most of the automated sanity tests, then I can focus on just what I'm working on.
Re: Windows Notepad App Remote Code Execution Vulnerability
#380Earlier quoted context omitted.
It’s just resumé driven development. Corporate droids gotta justify their salaries somehow. It doesn’t pay to call software “done”.
Individual developers or even developer management doesn't get much of a say in product direction at large corporations. The product management folks are who decide what features go in and when.
- Successfully led key efforts to modernize aging platform technologies
- Directed integration of cutting-edge system-wide artificial intelligence functionality