← Back

CVE-2021-22921

nvd nist
Published: Jul 12, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

Affected (4)

1 product
Node.js
1 product
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Nodejs
From 12.0.0 to 12.22.2
From 14.0.0 to 14.17.2
From 16.0.0 to 16.4.1
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.1.1

References (8)

Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
ExploitThird Party Advisory
Source: support@hackerone.com
PatchRelease NotesVendor Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.