This advisory has been withdrawn because it is a duplicate of GHSA-m2mx-rfpw-jghv. This link is maintained to preserve external references.
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
{
"cwe_ids": [
"CWE-427"
],
"github_reviewed": true,
"github_reviewed_at": "2023-07-13T00:12:02Z",
"nvd_published_at": "2020-05-16T12:15:00Z",
"severity": "HIGH"
}