Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/ | patch vendor advisory release notes |
https://hackerone.com/reports/1211160 | third party advisory exploit |
https://security.netapp.com/advisory/ntap-20210805-0003/ | third party advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | third party advisory patch |