← All CVEs

CVE-2021-3156

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-06Remediation due 2022-04-27

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

7.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2021-01-26
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-193

Affected products

VendorProductAffected versions
sudo_projectsudo>= 1.8.2, < 1.8.32
sudo_projectsudo>= 1.9.0, < 1.9.5
sudo_projectsudo1.9.5
sudo_projectsudo1.9.5
fedoraprojectfedora32
fedoraprojectfedora33
debiandebian_linux9.0
debiandebian_linux10.0
netappactive_iq_unified_managerall versions
netappcloud_backupall versions
netapphci_management_nodeall versions
netapponcommand_unified_manager_core_packageall versions
netappontap_select_deploy_administration_utilityall versions
netappontap_tools9
netappsolidfireall versions
mcafeeweb_gateway8.2.17
mcafeeweb_gateway9.2.8
mcafeeweb_gateway10.0.4
synologydiskstation_manager_unified_controller3.0
synologydiskstation_manager6.2
synologyskynas_firmwareall versions
synologyskynasall versions
synologyvs960hd_firmwareall versions
synologyvs960hdall versions
beyondtrustprivilege_management_for_mac< 21.1.1
beyondtrustprivilege_management_for_unix/linux< 10.3.2-10
oraclemicros_compact_workstation_3_firmware310
oraclemicros_compact_workstation_3all versions
oraclemicros_es400_firmware>= 400, <= 410
oraclemicros_es400all versions
oraclemicros_kitchen_display_system_firmware210
oraclemicros_kitchen_display_systemall versions
oraclemicros_workstation_5a_firmware5a
oraclemicros_workstation_5aall versions
oraclemicros_workstation_6_firmware>= 610, <= 655
oraclemicros_workstation_6all versions
oraclecommunications_performance_intelligence_center>= 10.3.0.0.0, <= 10.3.0.2.1
oraclecommunications_performance_intelligence_center>= 10.4.0.1.0, <= 10.4.0.3.1
oracletekelec_platform_distribution>= 7.4.0, <= 7.7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-3156