The vulnerability comes from the way Notepad handles Markdown hyperlinks. Attackers craft malicious .md files with embedded links that trigger unverified protocol handlers when users click them, ...