Junglewise Threat Intelligence

kerberos DLL injection in kerberos_sspi

Severity: low · CVSS 3.1 · Published 2022-05-24

Vendors: npm.

Executive brief

The kerberos npm package for Node.js is vulnerable to DLL injection attacks that allow attackers to execute arbitrary code and escalate privileges on Windows systems. This affects authentication services that rely on the kerberos package for Kerberos protocol support, potentially enabling complete system compromise.

Technical details

The kerberos package before version 1.0.0 contains an insecure DLL loading vulnerability (CWE-427) in the kerberos_sspi LoadLibrary() method due to unsafe DLL path search behavior. An attacker can inject malicious DLLs into the search path to achieve arbitrary code execution and privilege escalation. The vulnerability requires local system access and user interaction to place the malicious DLL, but once loaded, allows full code execution in the context of the Node.js process. The vulnerability was fixed in version 1.0.0 of the kerberos package.

Affected products

  • npm kerberos before 1.0.0

Timeline

  • 2020-05-16: disclosed
  • 2020: patched: Fixed in version 1.0.0
  • 2022-05-24: advisory: Advisory published; later withdrawn as duplicate
  • 2023-08-21: other: Advisory withdrawn as duplicate of GHSA-m2mx-rfpw-jghv

References