EXPOSURES › CVE-2021-3156
CVE-2021-3156
HIGH ⌖ ON CISA KEV · EXPLOITEDSudo's off-by-one heap buffer overflow allows privilege escalation and is actively exploited in the wild.
Sudo's CVE-2021-3156 contains an off-by-one error causing a heap-based buffer overflow that enables privilege escalation. This vulnerability is listed in CISA's KEV catalog, indicating it is actively exploited in the wild, posing a severe risk to systems relying on Sudo for privilege management. DIB organizations must ensure their Sudo versions are patched immediately to prevent attackers from escalating privileges and compromising system integrity.
Shame score — A known, actively exploited vulnerability in a critical system utility like Sudo demonstrates severe negligence and exposes organizations to immediate, high-impact compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.