CVE-2021-22921

Severity
7.8HIGH
EPSS
0.5%
top 32.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateJul 13

Description

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5nodejs/node4.04.*+12
NVDnodejs/node.js12.0.012.22.2+2

Patches

🔴Vulnerability Details

2
GHSA
Incorrect Permission Assignment for Critical Resource in Node2021-07-13
CVEList
CVE-2021-22921: Node2021-07-12

📋Vendor Advisories

1
Debian
CVE-2021-22921: nodejs - Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege esc...2021
CVE-2021-22921 (HIGH CVSS 7.8) | Node.js before 16.4.1 | cvebase.io