New Delhi: Microsoft has officially announced that it has fixed a security flaw in Notepad that could have enabled attackers to trick users into clicking harmful links inside Markdown files. The company has also resolved the issue in its latest patch updates by rolling out the fix to block any possible exploitation. The vulnerability could have been used to remotely load and run malicious files on the victim’s computer. Microsoft has also stated there is no evidence that the flaw was actively exploited. The problem affected Markdown files opened in Notepad.
Markdown files are simple text files that use a lightweight formatting language called Markdown. They let the users add some of the basic formatting, which includes headings, bold text, links, lists, and images, using plain text symbols. If the users clicked on the specifically crafted malicious link inside one of these files, it could trigger what Microsoft has described as the unverified protocols. This would enable the attackers to execute the remote code on the system.
Microsoft added support for Markdown in Notepad on Windows 11 last year. The latest feature enables users to open and edit Markdown files directly in the basic text editor. The addition was reported to have drawn criticism, with some stating that Microsoft was adding the necessary features and AI capabilities into the core applications, such as Notepad and Paint, contributing to the concerns about the bloatware in the operating system. There is no evidence that the hackers exploited the flaw in real-world attacks. It chose to patch the issue as part of its regular security updates. The fix ensures that Notepad no longer enables such links to launch unsafe protocols that could compromise the device.









