高危
Notepad++WinGUp Updater远程代码执行漏洞
2026-02-03 00:50:29 公开 ,2026-03-05 15:29:21 更新
- CISA KEV
- 关键漏洞
- 无需认证
- 远程
- 公开PoC
- CWEs:
- CWE-494 (Download of Code Without Integrity Check)
- CAPEC:
- CAPEC-184 (Software Integrity Attack) 、 CAPEC-185 (Malicious Software Download) 、 CAPEC-186 (Malicious Software Update) 、 CAPEC-187 (Malicious Automated Software Update via Redirection) 、 CAPEC-533 (Malicious Manual Software Update) 、 CAPEC-538 (Open-Source Library Manipulation) 、 CAPEC-657 (Malicious Automated Software Update via Spoofing) 、 CAPEC-662 (Adversary in the Browser (AiTB)) 、 CAPEC-691 (Spoof Open-Source Software Metadata) 、 CAPEC-692 (Spoof Version Control System Commit Metadata) 、 CAPEC-693 (StarJacking) 、 CAPEC-695 (Repo Jacking)
- SSVC:
- 可利用状态:已被积极利用攻击自动化:否技术影响评估:全部 2026-02-13 12:56:27