peter bassill · operator
$ cve CVE-2021-35064 JSON

CVE-2021-35064 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 70.8% (pctl 99)

Patch early

A public exploit exists.

Description

KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS70.75% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-269
On CISA KEVno
Public exploityes
Published2021-07-12
Last modified2026-06-17

Affected (1)

VendorProduct
krameravviaware

Public exploits

SourceTitleDate
exploit-dbKramer VIAware - Remote Code Execution (RCE) (Root)2022-04-07

References

→ the Explorer  ·  watch your stack  ·  NVD