Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-32223

Опубликовано: 14 июл. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.3

Описание

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, node.exe will search for providers.dll in the current user directory.After that, node.exe will try to search for providers.dll by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file providers.dll under a variety of paths and exploit this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

18.13.0+dfsg1-1ubuntu2
esm-apps/bionic

not-affected

8.10.0~dfsg-2ubuntu0.4+esm3
esm-apps/focal

not-affected

10.19.0~dfsg-3ubuntu1.2
esm-apps/jammy

not-affected

12.22.9~dfsg-1ubuntu3.1
esm-apps/xenial

not-affected

4.2.6~dfsg-1ubuntu4.2+esm2
esm-infra-legacy/trusty

not-affected

0.10.25~dfsg2-2ubuntu1.2+esm1
focal

not-affected

10.19.0~dfsg-3ubuntu1.2
impish

ignored

end of life
jammy

not-affected

12.22.9~dfsg-1ubuntu3.1

Показывать по

EPSS

Процентиль: 92%
0.09405
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
почти 3 года назад

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

CVSS3: 7.3
debian
почти 3 года назад

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under ce ...

CVSS3: 7.3
github
почти 3 года назад

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

CVSS3: 7.3
fstec
почти 3 года назад

Уязвимость библиотеки providers.dll программной платформы Node.js, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 92%
0.09405
Низкий

7.3 High

CVSS3