Junglewise Threat Intelligence

CVE-2020-13110: MongoDB Kerberos DLL injection

CVE-2020-13110 · Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: MongoDB.

Executive brief

The Kerberos library for Node.js loads dynamic libraries without specifying their full file paths, allowing an attacker to place a malicious DLL with the same name in a directory that precedes the legitimate library in the system's search path. This could enable arbitrary code execution on machines running affected versions of the library.

Technical details

The vulnerability is a DLL injection flaw (CWE-427) in the Kerberos npm package versions prior to 1.0.0. The library loads DLL dependencies without specifying absolute file paths, allowing an attacker to place a malicious DLL with an identical name in a directory that precedes the legitimate library in the DLL search path. This precondition requires local access and user interaction to be effective. A successful exploit results in arbitrary code execution with the privileges of the affected application. Upgrading to version 1.0.0 or later resolves the vulnerability.

Affected products

  • MongoDB Kerberos prior to 1.0.0

Timeline

  • 2020-09-04: disclosed
  • 2020-05-15: other: Vulnerability analysis published

References