Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Deepsurface-Robert

Researcher fromDeepSurface Security
#33196of 53,622
7.8Total CVSS
Vulnerabilities · 1
PT-2021-15277
7.8
2021-07-12
Node.Js · Node.Js · CVE-2021-22921
**Name of the Vulnerable Software and Affected Versions** Node.js versions prior to 16.4.1 Node.js versions prior to 14.17.2 Node.js versions prior to 12.22.2 **Description** The issue allows for local privilege escalation attacks under certain conditions on Windows platforms due to improper configuration of permissions in the installation directory. This can lead to two different escalation attacks: PATH and DLL hijacking. **Recommendations** For versions prior to 16.4.1, update to version 16.4.1 or later. For versions prior to 14.17.2, update to version 14.17.2 or later. For versions prior to 12.22.2, update to version 12.22.2 or later.