Live data from Hacker News

Windows Notepad App Remote Code Execution Vulnerability

cve.org

501–510 of 538 posts

Re: Windows Notepad App Remote Code Execution Vulnerability

#501
post #249

Earlier quoted context omitted.

>At some point, they need to stop asking "can we add this feature?" and start asking "does this text editor need a network-aware rendering stack?" But so far as I can tell the bug isn't related to "network-aware rendering stack" or AI (as other people are blindly speculating)? From MSRC: >How could an attacker exploit this vulnerability? >An attacker could trick a user into clicking a malicious link inside a Markdown…

That's why we have text editors, markdown viewers, image viewers, etc. You were never able to "click a link" in Notepad in the past. Mixing responsibilities brings with it lots of baggage, security vulnerabilities being one of them.

> That's why we have text editors, markdown viewers, image viewers, etc.

This is so 80s. Now we have systemd (svchost.exe), wayland (explorer) and a webbrowser (chrome). You don't need more.

Re: Windows Notepad App Remote Code Execution Vulnerability

#502

Earlier quoted context omitted.

That's why we have text editors, markdown viewers, image viewers, etc. You were never able to "click a link" in Notepad in the past. Mixing responsibilities brings with it lots of baggage, security vulnerabilities being one of them.

I think there are more text editors around that render clickable links than there are that don't. Even your terminal probably renders clickable links. Despite the scary words and score this wouldn't even be a vulnerability if people weren't so hard wired to click every link they see. It's not some URL parsing gone wrong triggering an RCE. Most likely they allowed something like file:// links which of course opens tha…

Ed doesn't.

Re: Windows Notepad App Remote Code Execution Vulnerability

#503

Earlier quoted context omitted.

I have the mspaint.exe from the same version too :P. It complains about registry stuff on launch but other than that it works fine. There's no spray can in the modern paint!

Why does it show registry error? I copied out mspaint.exe and some resource files as well were needed. It runs for me without error.

No idea. Probably because I'm on a work machine and need admin permission to make registry changes or something

Re: Windows Notepad App Remote Code Execution Vulnerability

#504
post #84

Earlier quoted context omitted.

I find notepad useful for sanitising clipboard content. No bold text, italics, bullet points, invisible html.. Just get the text and can copy it to paste again somewhere else. Ala Cmd+Shift+V on Mac

I somewhat regularly use the almost embarrassing key sequence Ctrl-C Ctrl-L Ctrl-V Ctrl-A Ctrl-X to sanitize text I’ve copied from a browser, using the address field to remove any formatting.

I use Edge’s address bar to de-wrap long URLs that have line wrapping and indentation in a proprietary packaging system’s SBOM. I paste in, then copy out the unwrapped URL to another application.

Re: Windows Notepad App Remote Code Execution Vulnerability

#505

Earlier quoted context omitted.

> If you walk away from an unlocked machine ...then I might as well ask what happens when I walk away from the encrypting edior while a file is still open. User Error can happen with any encryption or security schema. Pointing out a trueism is not an argument. > It's also portable So is encrypting files using a specialized tool. I don't need my editor to do this. The entire point of my criticism, and indeed the entir…

For what it's worth I understood the argument and think it is valid. It's one thing for the file you're working on to be vulnerable if you walk away leaving the editor open; it's another for all of your other files to be vulnerable too. It's O(1) vs. O(n). The difference is clearly not zero.

> It's one thing for the file you're working on to be vulnerable if you walk away leaving the editor open

Considering that walking away from an open editor means also walking away from an unlocked machine, the problem would be the exact same ;-)

Re: Windows Notepad App Remote Code Execution Vulnerability

#506

I found a copy of the win98 (I believe) notepad.exe a while back, and it works perfectly on windows 11 (though the "about notepad" dialog shows the windows 11 version for some reason??). I can write text into it, save it, and load text again. What more does notepad need? And it has a very nostalgic font too

> though the "about notepad" dialog shows the windows 11 version for some reason??

For many built in windows apps, the 'about this program' menu item just invokes a separate program, 'winver'. If you go Start -> Run and type in winver, it does the same thing.

Re: Windows Notepad App Remote Code Execution Vulnerability

#507
post #493

Earlier quoted context omitted.

Looks like they logged in the first time in years to make a post https://news.ycombinator.com/item?id=46975123 And decided to jump in on some threads just as well.

That post also looks suspiciously like AI slop

Yep. Two latest comments are full of LLM tells, plus an LLM-generated Show HN.

As usual with modern Claudes and GPT-5s, the output repeats and overemphasizes jargon from the input tokens without clarifying or switching up the wording.

Re: Windows Notepad App Remote Code Execution Vulnerability

#508
post #446

Earlier quoted context omitted.

Win+r, ctrl+v, ctrl+a, ctrl+x, esc does this without spawning a non ephemeral window

Unfortunately this has a 260 character limit.

Interesting and valid point. TIL!

Re: Windows Notepad App Remote Code Execution Vulnerability

#509
post #197

Earlier quoted context omitted.

> nailing down Unicode and text encodings was still considered rocket science. Now this is a solved problem I wish… Detecting text encoding is only easy if all you need to contend with is UTF16-with-BOM, UTF8-with-BOM, UTF8-without-BOM, and plain ASCII (which is effectively also UTF8). As soon as you might see UTF16 or UCS without a BOM, or 8-bit codepages other than plain ASCII (many apps/libs assume that these are…

The very fact that UTF-8 itself discouraged from using the BOM is just so alien to me. I understand they want it to be the last encoding and therefore not in need of a explicit indicator, but as it currently IS NOT the only encoding that is used, it makes is just so difficult to understand if I'm reading any of the weird ASCII derivatives or actual Unicode. It's maddening and it's frustrating. The US doesn't have any…

> The very fact that UTF-8 itself discouraged from using the BOM is just so alien to me.

One of the key advantages of UTF8 is that all ASCII content is effectively UTF-8. Having the BOM present reduces that convenience a bit, and a file starting with the three bytes 0xEF,0xBB,0xBF may be mistaken by some tools for a binary file rather than readable text.

Re: Windows Notepad App Remote Code Execution Vulnerability

#510

Earlier quoted context omitted.

Microsoft is Windows. Anyone saying otherwise is completely delusional. Most of M$ office software has alternatives (Google Docs, OpenOffice...), M$ has no AI model and no AI labs to speak of, Github is constantly crashing and burning, Azure is garbage, and they uttery killed Xbox. Oh and Linkedin is for actual psychopaths. If Windows dies, all of their other junk that is attached to the platform will die as well.

Holding one's unsubstantiated personal beliefs above all evidence and rational argument is, in fact, delusion. The evidence in TFA is that Microsoft is much more than Windows. So much more in fact that one can make a very reasonable argument that it's no longer a top priority for them. The delusion is shutting your eyes, covering your ears, and screaming about how literally everyone except you is wrong.

While I certainly don't agree in the phrasing or even in the general framing of GP, I think there's a point to be made that might not be in the quantifiable data.

The data putting Windows a ways down in revenue is likely correct, but I would argue that losing Windows could mean losing the others as well. Windows is their funnel to most other offerings (currently). Why is MS Office the standard? Why is Azure used? I know for certain that many purchases of Office and Azure were made because of legacy corporate policy of basing IT around Windows/AD. If everyone switched to Linux or MacOS, a lot of seemingly separate Microsoft products would probably die as a downstream effect.

Post reply on HN