{"id":286245,"date":"2026-02-11T19:41:11","date_gmt":"2026-02-11T19:41:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/286245\/"},"modified":"2026-02-11T19:41:11","modified_gmt":"2026-02-11T19:41:11","slug":"microsoft-fixes-notepad-flaw-that-could-trick-users-into-clicking-malicious-markdown-links","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/286245\/","title":{"rendered":"Microsoft fixes Notepad flaw that could trick users into clicking malicious Markdown links"},"content":{"rendered":"<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Microsoft has fixed a serious security vulnerability affecting Markdown files in Notepad. In the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-20841\" rel=\"nofollow noopener\" target=\"_blank\">company\u2019s Tuesday patch notes<\/a>, Microsoft says a bad actor could carry out a remote code execution attack by tricking users \u201cinto clicking a malicious link inside a Markdown file opened in Notepad,\u201d as <a href=\"https:\/\/www.theregister.com\/2026\/02\/11\/notepad_rce_flaw\/\" rel=\"nofollow noopener\" target=\"_blank\">reported earlier by The Register<\/a>.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Clicking the link would \u201claunch unverified protocols,\u201d allowing attackers to remotely load and execute malicious files on a victim\u2019s computer, according to the patch notes. Microsoft says there isn\u2019t any evidence of attackers exploiting the Notepad vulnerability (<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-20841\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-20841<\/a>) in the wild, but it issued a fix for the flaw in its Tuesday patch.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Microsoft initially <a href=\"https:\/\/www.theverge.com\/news\/677474\/microsoft-windows-notepad-bold-italic-text-formatting-markdown-support\" rel=\"nofollow noopener\" target=\"_blank\">added support<\/a> for Markdown, a plaintext formatting language, to Notepad on Windows 11 last May. The move contributed to <a href=\"https:\/\/www.theverge.com\/tech\/870045\/microsoft-windows-11-issues-rebuilding-trust-notepad\" rel=\"nofollow noopener\" target=\"_blank\">criticism that Microsoft<\/a> is filling its operating system with bloatware, including by stuffing new features and AI capabilities into <a href=\"https:\/\/www.theverge.com\/news\/672984\/microsoft-notepad-paint-snipping-tool-generative-ai-windows-insiders\" rel=\"nofollow noopener\" target=\"_blank\">apps like Notepad<\/a> and <a href=\"https:\/\/www.theverge.com\/news\/866524\/microsoft-paint-notepad-ai-coloring-book\" rel=\"nofollow noopener\" target=\"_blank\">Paint<\/a>.<\/p>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Notepad isn\u2019t the only text editor that has faced security issues recently, <a href=\"https:\/\/www.theverge.com\/tech\/872462\/notepad-plus-plus-server-hijacking\" rel=\"nofollow noopener\" target=\"_blank\">as the third-party Notepad++ app<\/a> disclosed that some users may have downloaded a malicious update linked to Chinese state-sponsored attackers.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has fixed a serious security vulnerability affecting Markdown files in Notepad. In the company\u2019s Tuesday patch notes,&hellip;\n","protected":false},"author":2,"featured_media":32865,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[8846,85,46,134,140,920,125],"class_list":["post-286245","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-apps","tag-il","tag-israel","tag-microsoft","tag-security","tag-tech","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/286245","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=286245"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/286245\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/32865"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=286245"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=286245"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=286245"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}