Executive brief
The Kerberos library for Node.js loads dynamic libraries without specifying their full file paths, allowing an attacker to place a malicious DLL with the same name in a directory that precedes the legitimate library in the system's search path. This could enable arbitrary code execution on machines running affected versions of the library.
Technical details
The vulnerability is a DLL injection flaw (CWE-427) in the Kerberos npm package versions prior to 1.0.0. The library loads DLL dependencies without specifying absolute file paths, allowing an attacker to place a malicious DLL with an identical name in a directory that precedes the legitimate library in the DLL search path. This precondition requires local access and user interaction to be effective. A successful exploit results in arbitrary code execution with the privileges of the affected application. Upgrading to version 1.0.0 or later resolves the vulnerability.
Affected products
- MongoDB Kerberos prior to 1.0.0
Timeline
- 2020-09-04: disclosed
- 2020-05-15: other: Vulnerability analysis published