PT-2017-10915 · Node.Js · Windows-Cpu

Published

2017-11-17

·

Updated

2020-09-01

·

CVE-2017-1000219

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions windows-cpu versions prior to 0.1.5
Description The issue allows for command injection, resulting in code execution as the Node.js user. Specifically, versions of windows-cpu before 0.1.5 are affected, where arbitrary code can be executed when passed into the first argument of the findLoad method, leading to remote code execution.
Recommendations Update to version 0.1.5 or later. As a temporary workaround, consider avoiding the use of the findLoad method with untrusted input until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000219
GHSA-63M4-FHF2-CMF7

Affected Products

Windows-Cpu