ZeroHour

CVE-2021-22921

PoC
CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
Modified
Description

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

Vendors
nodejssiemens
Products
node.js, sinec infrastructure network services
Weakness
CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.