QID 376746
Date Published: 2022-07-26
QID 376746: Node.js DLL Hijacking Vulnerabilities (JULY 2022)
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside of a web browser.
Affected Versions:
Node.js version 16.X series all versions up to 16.16.0
Node.js version 14.X series all versions up to 14.20.0
QID Detection Logic:(Authenticated)
This QID checks for the vulnerable version of node.js at HKLM\SOFTWARE\Node.js
Attackers can exploit this vulnerability to escalate their privileges and establish persistence in a target environment.
Solution
The vendors have released fixed version of Node.js node.js
Vendor References
- july-2022-security-releases -
nodejs.org/en/blog/vulnerability/july-2022-security-releases/
CVEs related to QID 376746
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| july-2022-security-releases |
|