peter bassill · operator
$ cve CVE-2021-3156 JSON

CVE-2021-3156 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-27.

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS99.96% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-193
On CISA KEVyes — remediate by 2022-04-27
Public exploityes
Published2021-01-26
Last modified2026-06-17

CISA KEV

NameSudo Heap-Based Buffer Overflow Vulnerability
Added2022-04-06
Due2022-04-27
Vendor / productSudo / Sudo
Ransomware usenone reported

Affected (31)

VendorProduct
beyondtrustprivilege management for mac
beyondtrustprivilege management for unix\/linux
debiandebian linux
fedoraprojectfedora
mcafeeweb gateway
netappactive iq unified manager
netappcloud backup
netapphci management node
netapponcommand unified manager core package
netappontap select deploy administration utility
netappontap tools
netappsolidfire
oraclecommunications performance intelligence center
oraclemicros compact workstation 3
oraclemicros compact workstation 3 firmware
oraclemicros es400
oraclemicros es400 firmware
oraclemicros kitchen display system
oraclemicros kitchen display system firmware
oraclemicros workstation 5a
oraclemicros workstation 5a firmware
oraclemicros workstation 6
oraclemicros workstation 6 firmware
oracletekelec platform distribution
sudo projectsudo
synologydiskstation manager
synologydiskstation manager unified controller
synologyskynas
synologyskynas firmware
synologyvs960hd
synologyvs960hd firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD