Skip to content
COOEY

EXPOSURES › CVE-2021-3156

CVE-2021-3156

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-3156 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedprivilege-escalation

Sudo's off-by-one heap buffer overflow allows privilege escalation and is actively exploited in the wild.

Sudo's CVE-2021-3156 contains an off-by-one error causing a heap-based buffer overflow that enables privilege escalation. This vulnerability is listed in CISA's KEV catalog, indicating it is actively exploited in the wild, posing a severe risk to systems relying on Sudo for privilege management. DIB organizations must ensure their Sudo versions are patched immediately to prevent attackers from escalating privileges and compromising system integrity.

Shame score — A known, actively exploited vulnerability in a critical system utility like Sudo demonstrates severe negligence and exposes organizations to immediate, high-impact compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.