Insecure DLL loading in Node.js - CVE-2022-32223

 

Insecure DLL loading in Node.js - CVE-2022-32223

Published: July 13, 2022 / Updated: October 25, 2022


Vulnerability identifier: #VU65276
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32223
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to elevate privileges on the system

The vulnerability exists due to DLL search order hijacking of providers.dll. A local attacker can place a specially crafted .dll file and elevate privileges on the system


Affected software

Node.js
Amazon Linux AMI
Answer Retrieval for Watson Discovery On Prem
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
IBM Planning Analytics Workspace
Voice Gateway
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Integration Bus
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Transformation Advisor
IBM Spectrum Protect Plus
Event Streams
IBM Cognos Controller
IBM App Connect Enterprise
IBM Cognos Analytics
nodejs

How to mitigate CVE-2022-32223

Install updates from vendor's website.

Node.js - addressed in versions 14.20.0, 16.16.0
Answer Retrieval for Watson Discovery On Prem - update to 2.8.0
Voice Gateway - addressed in versions 1.0.8.0, 1.0.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
Event Streams - update to 11.0.4
IBM Cognos Controller - update to 11.0.1.0.3
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-9, 2022.2-1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-8, 2022.2.1-1
IBM Planning Analytics Workspace - update to 2.0.82
IBM Cloud Transformation Advisor - update to 3.2.2
IBM Spectrum Protect Plus - update to 10.1.12
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
nodejs - update to 18.12.1-1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins