CVE-2021-22921: High severity ibm cognos controller vulnerability
Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.
Other sources
Node.js could allow a local attacker to gain elevated privileges on the system, caused by improper configuration of permissions in the installation directory. Under certain conditions. An attacker could exploit this vulnerability to perform PATH and DLL hijacking attacks.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22921?
CVE-2021-22921 is a vulnerability in Node.js that could allow a local attacker to gain elevated privileges on the system.
How does CVE-2021-22921 work?
CVE-2021-22921 is caused by improper configuration of permissions in the installation directory of Node.js, which can be exploited by a local attacker to perform PATH and DLL hijacking attacks.
What is the severity of CVE-2021-22921?
CVE-2021-22921 has a severity rating of high, with a CVSS score of 7.4.
How can CVE-2021-22921 be exploited?
CVE-2021-22921 can be exploited by a local attacker who has access to the installation directory of Node.js, allowing them to manipulate the PATH environment variable and potentially execute malicious code.
Is there a fix for CVE-2021-22921?
To fix CVE-2021-22921, it is recommended to update Node.js to the latest version and ensure proper configuration of permissions in the installation directory.