PT-2017-10915 · Node.Js · Windows-Cpu

Publicado

2017-11-17

·

Atualizado

2020-09-01

·

CVE-2017-1000219

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions windows-cpu versions prior to 0.1.5
Description The issue allows for command injection, resulting in code execution as the Node.js user. Specifically, versions of windows-cpu before 0.1.5 are affected, where arbitrary code can be executed when passed into the first argument of the findLoad method, leading to remote code execution.
Recommendations Update to version 0.1.5 or later. As a temporary workaround, consider avoiding the use of the findLoad method with untrusted input until the issue is resolved.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000219
GHSA-63M4-FHF2-CMF7

Produtos afetados

Windows-Cpu