Use Notepad Quick Update 🚨
Microsoft issued a serious vulnerability patch in Notepad on Windows 11 after it encountered a CVE-2026-20841 code security problem, which is classified as a Remote Code Execution (RCE) type vulnerability and has a severity rating of up to 8.8 according to the CVSS standard. This vulnerability gives an attacker the opportunity to remotely execute malicious code on the victim machine if the user opens a file that is designed to attack and clicks a link within such a file.
.
The cause of the problem stems from the Markdown display feature in a new version of Notepad from the Microsoft Store, which supports clickable links but has a URI Scheme check flaw, allowing non-hopefuls to embed special links such as file: / / or other protocols into .md files.
.
When a user opens a file and clicks a specially created link, the system may immediately command without the user's knowledge and no security alert window appears. This results in the ability to download malware or take control of the machine. All processes can work even with User permissions. If the active account has Admin permissions, the damage can be even more severe.
.
This vulnerability hits Notepad versions before 11.2510, especially versions installed through the Microsoft Store. Although there are no reports of widespread deployment attacks, the nature of the RCE vulnerability is considered a high risk that should not be overlooked.
.
Microsoft has released an update to fix this vulnerability. Users can enter the Microsoft Store to the Download menu, then press Get Updates to update Notepad to the latest version with Windows Update fully installed. It is best to avoid opening .md files from untrusted sources and not clicking strange links within text files to prevent potential unwitting risks.
.
Source: bleepingcomputer
หลายคนค้นหา “notepad jpg” เพราะอยากรู้ว่า Notepad เปิดไฟล์ .jpg ได้ไหม หรือเปิดแล้วจะเป็นอะไร ขอเล่าจากที่เจอเองแบบเข้าใจง่ายนะ 1) Notepad เปิดไฟล์ .jpg ได้ไหม? โดยปกติ Notepad เป็นโปรแกรมอ่าน/แก้ไข “ไฟล์ข้อความ” (plain text) ไม่ใช่โปรแกรมดูรูป ดังนั้นถ้าลากไฟล์ .jpg ไปเปิดใน Notepad มันจะไม่แสดงภาพ แต่จะแสดงเป็นอักขระมั่ว ๆ (เพราะ .jpg เป็นไฟล์ไบนารี) ซึ่งไม่ได้แปลว่าไฟล์เสีย แค่ Notepad อ่านข้อมูลรูปแบบนั้นไม่รู้เรื่องเท่านั้น 2) แล้วทำไมคนถึงเอา .jpg มาเกี่ยวกับ Notepad? บางครั้งเราต้องการ “ดูข้อความที่ซ่อนอยู่” หรือ “เช็กไฟล์” เช่น: - ตรวจว่าไฟล์ที่ได้มาจริง ๆ เป็น .jpg หรือแอบปลอมเป็นอย่างอื่น (เช่น ไฟล์ที่ควรเป็นรูป แต่จริง ๆ เป็นสคริปต์/ไฟล์แนบแปลก ๆ) - เปิดดู header คร่าว ๆ (ไฟล์ JPG มักขึ้นต้นด้วยค่าบางอย่าง) แต่สำหรับผู้ใช้ทั่วไป วิธีนี้ไม่ค่อยจำเป็น เพราะมีวิธีที่ปลอดภัยและง่ายกว่า 3) วิธีเปิดรูป .jpg ที่ถูกต้องบน Windows 11 ถ้าต้องการดูรูป ให้ใช้ Photos (แอปรูปภาพ), Paint, หรือโปรแกรมดูรูปอื่น ๆ จะเหมาะที่สุด ถ้าไฟล์เปิดไม่ได้ค่อยไล่เช็กว่าไฟล์เสียหรือสกุลไม่ตรง 4) จุดที่ “ต้องระวัง” มากกว่าเรื่องเปิด .jpg: ช่องโหว่ Notepad บน Windows 11 จากข่าวล่าสุด Notepad เวอร์ชันจาก Microsoft Store (ก่อน 11.2510) มีช่องโหว่ร้ายแรง CVE-2026-20841 คะแนน CVSS 8.8/10 เกี่ยวกับฟีเจอร์แสดงผล Markdown ที่ทำให้ “ลิงก์คลิกได้” ในไฟล์ .md และมีปัญหาการตรวจสอบ URI scheme (เช่น file://) ถ้าเราเปิดไฟล์ .md แปลก ๆ แล้วเผลอคลิกลิงก์ อาจโดนสั่งรันอะไรบางอย่างได้แบบไม่รู้ตัว (แนว Remote Code Execution) 5) อัปเดต Notepad ให้ปลอดภัย (แนะนำทำทันที) - เปิด Microsoft Store - ไปที่ Library / Download - กด Get updates - อัปเดต Notepad ให้เป็นเวอร์ชันล่าสุด และอย่าลืมกด Windows Update ให้ครบด้วย 6) ทริคความปลอดภัยเวลาเจอไฟล์จากแหล่งไม่น่าไว้ใจ - หลีกเลี่ยงการเปิดไฟล์ .md/.txt ที่แนบมาจากแชต/อีเมลแปลก ๆ โดยเฉพาะไฟล์ที่ชวนให้ “คลิกลิงก์” - ถ้าจำเป็นต้องดู ให้เปิดแบบอ่านอย่างเดียว และอย่าคลิกลิงก์ในไฟล์ - ถ้าเป็นไฟล์รูป .jpg ที่น่าสงสัย ให้สแกนด้วย Windows Security ก่อน และตรวจนามสกุลไฟล์ให้ชัด สรุปสั้น ๆ: “notepad jpg” เปิดได้แต่ไม่เห็นรูป (เห็นเป็นตัวอักษรมั่ว) แต่ประเด็นสำคัญตอนนี้คือรีบอัปเดต Notepad บน Windows 11 เพื่ออุดช่องโหว่ร้ายแรง โดยเฉพาะถ้าคุณใช้ Notepad จาก Microsoft Store และเคยเปิดไฟล์ Markdown (.md) จากแหล่งที่ไม่ชัวร์

