CVE-2021-3156 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-27.
Description
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.96% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-193 |
| On CISA KEV | yes — remediate by 2022-04-27 |
| Public exploit | yes |
| Published | 2021-01-26 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Sudo Heap-Based Buffer Overflow Vulnerability |
|---|---|
| Added | 2022-04-06 |
| Due | 2022-04-27 |
| Vendor / product | Sudo / Sudo |
| Ransomware use | none reported |
Affected (31)
| Vendor | Product |
|---|---|
| beyondtrust | privilege management for mac |
| beyondtrust | privilege management for unix\/linux |
| debian | debian linux |
| fedoraproject | fedora |
| mcafee | web gateway |
| netapp | active iq unified manager |
| netapp | cloud backup |
| netapp | hci management node |
| netapp | oncommand unified manager core package |
| netapp | ontap select deploy administration utility |
| netapp | ontap tools |
| netapp | solidfire |
| oracle | communications performance intelligence center |
| oracle | micros compact workstation 3 |
| oracle | micros compact workstation 3 firmware |
| oracle | micros es400 |
| oracle | micros es400 firmware |
| oracle | micros kitchen display system |
| oracle | micros kitchen display system firmware |
| oracle | micros workstation 5a |
| oracle | micros workstation 5a firmware |
| oracle | micros workstation 6 |
| oracle | micros workstation 6 firmware |
| oracle | tekelec platform distribution |
| sudo project | sudo |
| synology | diskstation manager |
| synology | diskstation manager unified controller |
| synology | skynas |
| synology | skynas firmware |
| synology | vs960hd |
| synology | vs960hd firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1) | 2021-02-03 |
| exploit-db | Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2) | 2021-02-03 |
References
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html
- http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2021/Feb/42
- http://seclists.org/fulldisclosure/2021/Jan/79
- http://seclists.org/fulldisclosure/2024/Feb/3
- http://www.openwall.com/lists/oss-security/2021/01/26/3
- http://www.openwall.com/lists/oss-security/2021/01/27/1
- http://www.openwall.com/lists/oss-security/2021/01/27/2
- http://www.openwall.com/lists/oss-security/2021/02/15/1
- http://www.openwall.com/lists/oss-security/2021/09/14/2
- http://www.openwall.com/lists/oss-security/2024/01/30/6
- http://www.openwall.com/lists/oss-security/2024/01/30/8
- https://kc.mcafee.com/corporate/index?page=content&id=SB10348
- https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/
- https://security.gentoo.org/glsa/202101-33
→ the Explorer · watch your stack · NVD