{"id":2320,"date":"2026-02-11T22:06:36","date_gmt":"2026-02-11T18:06:36","guid":{"rendered":"https:\/\/www.actutech.app\/microsoft-fixes-notepad-flaw-that-could-trick-users-into-clicking-malicious-markdown-links\/"},"modified":"2026-02-11T22:06:36","modified_gmt":"2026-02-11T18:06:36","slug":"microsoft-fixes-notepad-flaw-that-could-trick-users-into-clicking-malicious-markdown-links","status":"publish","type":"post","link":"https:\/\/www.actutech.app\/en\/microsoft-fixes-notepad-flaw-that-could-trick-users-into-clicking-malicious-markdown-links\/","title":{"rendered":"Microsoft fixes Notepad flaw that could trick users into clicking malicious Markdown links"},"content":{"rendered":"<figure>\n<p><img decoding=\"async\" alt=\"The Microsoft Windows logo on an illustrated background.\" data-caption=\"\" data-portal-copyright=\"Image: The Verge\" data-has-syndication-rights=\"1\" src=\"https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/02\/STK109_WINDOWS_C.jpg?quality=90&amp;strip=all&amp;crop=0,0,100,100\" \/><figcaption>\n\t\t<\/figcaption><\/p><\/figure>\n<p class=\"has-text-align-none\">Microsoft has fixed a serious security vulnerability affecting Markdown files in Notepad. In the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-20841\" target=\"_blank\" rel=\"noopener\">company&rsquo;s Tuesday patch notes<\/a>, Microsoft says a bad actor could carry out a remote code execution attack by tricking users \u00ab\u00a0into clicking a malicious link inside a Markdown file opened in Notepad,\u00a0\u00bb as <a href=\"https:\/\/www.theregister.com\/2026\/02\/11\/notepad_rce_flaw\/\" target=\"_blank\" rel=\"noopener\">reported earlier by <em>The Register<\/em><\/a>.<\/p>\n<p class=\"has-text-align-none\">Clicking the link would \u00ab\u00a0launch unverified protocols,\u00a0\u00bb allowing attackers to remotely load and execute malicious files on a victim&rsquo;s computer, according to the patch notes. Microsoft says there isn&rsquo;t any evidence of attackers exploiting the Notepad vulnerability (<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-20841\" target=\"_blank\" rel=\"noopener\">CVE-2026-20841<\/a>) in the wild, but it issued a fix for \u2026<\/p>\n<p><a href=\"https:\/\/www.theverge.com\/tech\/877295\/microsoft-notepad-markdown-security-vulnerability-remote-code-execution\" target=\"_blank\" rel=\"noopener\">Read the full story at The Verge.<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft has fixed a serious security vulnerability affecting Markdown files in Notepad. In the company&rsquo;s Tuesday patch notes, Microsoft says [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2320","post","type-post","status-publish","format-standard","hentry","category-non-classe"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/posts\/2320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/comments?post=2320"}],"version-history":[{"count":0,"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/posts\/2320\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/media?parent=2320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/categories?post=2320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.actutech.app\/en\/wp-json\/wp\/v2\/tags?post=2320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}