Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-22921

Опубликовано: 12 июл. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.4
CVSS3: 7.8

Описание

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

РелизСтатусПримечание
bionic

not-affected

devel

not-affected

esm-apps/bionic

not-affected

esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

not-affected

focal

not-affected

groovy

not-affected

hirsute

not-affected

Показывать по

EPSS

Процентиль: 73%
0.00821
Низкий

4.4 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

CVSS3: 7.8
debian
почти 4 года назад

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local pri ...

CVSS3: 7.8
github
почти 4 года назад

Incorrect Permission Assignment for Critical Resource in Node

EPSS

Процентиль: 73%
0.00821
Низкий

4.4 Medium

CVSS2

7.8 High

CVSS3