Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade nodeUpgrade node14 | Nov 4, 2022 | Sep 21, 2021 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-14 to version 14.17.6-11.4.38.0.1.101.2 on Solaris 11.4Upgrade runtime/nodejs/nodejs-12 to version 12.22.5-11.4.38.0.1.101.2 on Solaris 11.4Upgrade runtime/nodejs to version 14.17.6-11.4.38.0.1.101.2 on Solaris 11.4 | Nov 17, 2021 | Jul 12, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub