Vulnerabilities > Kerberos Project > Kerberos > 0.0.24

DATE CVE VULNERABILITY TITLE RISK
2020-05-16 CVE-2020-13110 Uncontrolled Search Path Element vulnerability in Kerberos Project Kerberos
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
local
low complexity
kerberos-project CWE-427
7.8