CVE-2020-13110
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
HIGH · CVSS 7.8
EPSS 0.00068
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules8
YARA rules0