logo

CVE-2022-32223 Discovery: DLL Hijacking via npm CLI

ID: 179c4aac-8220-53b5-a640-0f730b901c23

STIX ID: report--179c4aac-8220-53b5-a640-0f730b901c23

Feed Name: Aqua Security Blog

Threat Score
65/100

Date Published: 2022-07-12

Date Updated: 2026-05-12

...
...

Aqua Team Nautilus disclosed CVE-2022-32223, a Windows DLL hijacking vulnerability in Node.js versions earlier than 16.16.0 (LTS) and 14.20.0 when OpenSSL is installed and an OpenSSL configuration points to a provider section (defaulting to providers). An attacker who can place a malicious providers.dll in a searched directory (notably the current working directory) can execute code in the context of the user running node/npm, enabling local privilege escalation, persistence, and stealthy supply-chain abuses via malicious packages; the issue was reported and patched (upgrade Node.js and avoid embedding untrusted binary artifacts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.