CVE-2021-3156

HIGHCVSS 7.8/10Actively ExploitedEPSS 99.30%

Last modified

CVE-2021-3156 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.30% chance of exploitation in the next 30 days.

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
99.30%

99.9th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
Sudo ProjectSudo>= 1.8.2, < 1.8.32
Sudo ProjectSudo>= 1.9.0, < 1.9.5
Sudo ProjectSudo1.9.5
FedoraprojectFedora32
FedoraprojectFedora33
DebianDebian Linux9.0
DebianDebian Linux10.0
NetappActive Iq Unified ManagerAll versions
NetappCloud BackupAll versions
NetappHci Management NodeAll versions
NetappOncommand Unified Manager Core PackageAll versions
NetappOntap Select Deploy Administration UtilityAll versions
NetappOntap Tools9
NetappSolidfireAll versions
McafeeWeb Gateway8.2.17
McafeeWeb Gateway9.2.8
McafeeWeb Gateway10.0.4
SynologyDiskstation Manager Unified Controller3.0
SynologyDiskstation Manager6.2
SynologySkynas FirmwareAll versions
SynologyVs960hd FirmwareAll versions
BeyondtrustPrivilege Management For Mac< 21.1.1
BeyondtrustPrivilege Management For Unix\/Linux< 10.3.2-10
OracleMicros Compact Workstation 3 Firmware310
OracleMicros Es400 Firmware>= 400, <= 410
OracleMicros Kitchen Display System Firmware210
OracleMicros Workstation 5a Firmware5a
OracleMicros Workstation 6 Firmware>= 610, <= 655
OracleCommunications Performance Intelligence Center>= 10.3.0.0.0, <= 10.3.0.2.1
OracleCommunications Performance Intelligence Center>= 10.4.0.1.0, <= 10.4.0.3.1
OracleTekelec Platform Distribution>= 7.4.0, <= 7.7.1

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2021-3156?
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
How severe is CVE-2021-3156?
CVE-2021-3156 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 99.30% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2021-3156?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3156?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST