CVE-2022-32223

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
14/07/2022
Last modified:
28/10/2022

Description

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 14.0.0 (including) 14.14.0 (including)
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 14.14.0 (including) 14.20.0 (excluding)
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 16.0.0 (including) 16.12.0 (including)
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 16.13.0 (including) 16.16.0 (excluding)
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 18.0.0 (including) 18.0.5 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*