Skip to content
COOEY

EXPOSURES › CVE-2016-3643

CVE-2016-3643

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-3643 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildprivilege-escalationunpatched

A sudo misconfiguration in SolarWinds Virtualization Manager allowed privilege escalation.

The vendor's own misconfigured sudo settings let attackers escalate privileges, proving that even well-known products can harbor avoidable flaws. DIBs must audit sudo configurations and patch known issues immediately, as this flaw was actively exploited in the wild.

Shame score — A misconfigured sudo setting is a classic, avoidable negligence that was actively exploited in the wild, showing a failure to secure a basic system component.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability in core management software poses significant risk, though no public fallout details are provided in the source.
cooey ↗ severe-fallout -0.60
Vulnerability in core management software poses significant risk, though no public fallout details are provided in the source.
"SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.