Skip to content
COOEY

EXPOSURES › CVE-2021-3493

CVE-2021-3493

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-3493 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 exploited-in-wildunpatchedrce

Linux Kernel unpatched for privilege escalation

A critical Linux Kernel vulnerability was actively exploited, allowing attackers to gain elevated privileges on affected systems.

Shame score — Active exploitation leading to unauthorized access and potential data breaches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.