Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2021-07-12T10:22:24

Updated: 2022-03-08T14:08:04

Reserved: 2021-01-06T00:00:00


Link: CVE-2021-22921

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-07-12T11:15:08.017

Modified: 2022-04-06T14:30:09.710


Link: CVE-2021-22921

JSON object: View

cve-icon Redhat Information

No data.

CWE