CVE-2022-32223 Discovery: DLL Hijacking via npm CLI
ID: 179c4aac-8220-53b5-a640-0f730b901c23
STIX ID: report--179c4aac-8220-53b5-a640-0f730b901c23
Feed Name: Aqua Security Blog
Aqua Team Nautilus disclosed CVE-2022-32223, a Windows DLL hijacking vulnerability in Node.js versions earlier than 16.16.0 (LTS) and 14.20.0 when OpenSSL is installed and an OpenSSL configuration points to a provider section (defaulting to providers). An attacker who can place a malicious providers.dll in a searched directory (notably the current working directory) can execute code in the context of the user running node/npm, enabling local privilege escalation, persistence, and stealthy supply-chain abuses via malicious packages; the issue was reported and patched (upgrade Node.js and avoid embedding untrusted binary artifacts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
