Users could be tricked into running arbitrary code, but the issue was patched last week.
According to Microsoft's release notes, the update fixes 25 elevation of privilege flaws, 12 remote code execution ...
The flaw exploits Notepad’s recently added support for Markdown, a formatting language used on websites and in files, to run malicious code on a Windows PC.