CVE-2021-3156
published 2021-01-26CVE-2021-3156: Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s"…
PriorityP189high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-27
Exploited in the wild
EPSS
99.30%
99.9th percentile
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| beyondtrust | privilege_management_for_mac | < 21.1.1 | 21.1.1 |
| beyondtrust | privilege_management_for_unix_linux | < 10.3.2-10 | 10.3.2-10 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sudo | < sudo 1.9.5p1-1.1 (bookworm) | sudo 1.9.5p1-1.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway | — | — |
| netapp | ontap_tools | — | — |
| oracle | communications_performance_intelligence_center | 10.3.0.0.0 – 10.3.0.2.1 | — |
| oracle | communications_performance_intelligence_center | 10.4.0.1.0 – 10.4.0.3.1 | — |
| oracle | micros_compact_workstation_3_firmware | — | — |
| oracle | micros_es400_firmware | 400 – 410 | — |
| oracle | micros_kitchen_display_system_firmware | — | — |
| oracle | micros_workstation_5a_firmware | — | — |
| oracle | micros_workstation_6_firmware | 610 – 655 | — |
| oracle | tekelec_platform_distribution | 7.4.0 – 7.7.1 | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_cloud_compute | — | — |
| paloalto | prisma_sd-wan | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | >= 0 < 1.9.5p1-1.1 | 1.9.5p1-1.1 |
| sudo_project | sudo | >= 0 < 1.9.5p1-1.1 | 1.9.5p1-1.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unexpected writes or modifications to /usr/bin/.dbus.log, which is used by the AuthDoor PAM backdoor (deployed alongside CVE-2021-3156 exploitation) to store captured credentials in ASCII hex format. ↗
- →Alert on replacement or unexpected modification of pam_unix.so or pam_unix2.so, as threat actors exploiting CVE-2021-3156 for privilege escalation were observed overwriting these PAM libraries with a backdoored version (AuthDoor). ↗
- →Monitor for files being created or executed under /var/spool/.network/, a directory used by the AuthDoor PAM backdoor for staging and executing additional payloads. ↗
- →Detect GTPDoor C2 activity by monitoring for unexpected UDP traffic on port 2123 (GTP-C), which the implant uses to tunnel command-and-control traffic after gaining access via CVE-2021-3156. ↗
- ·The vulnerability is exploitable in the default sudo configuration; no special sudoers policy or privileges are required for a non-root user to trigger the heap overflow. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w5vh-2923-gp5c: Sudo before 1
ghsa_unreviewed·2022-05-24
CVE-2021-3156 [HIGH] CWE-193 GHSA-w5vh-2923-gp5c: Sudo before 1
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character:
OSV
sudo vulnerability
osv·2021-01-27·CVSS 7.8
CVE-2021-3156 [HIGH] sudo vulnerability
sudo vulnerability
USN-4705-1 fixed a vulnerability in Sudo. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Sudo incorrectly handled memory when parsing command
lines. A local attacker could possibly use this issue to obtain unintended
access to the administrator account. (CVE-2021-3156)
OSV
sudo vulnerabilities
osv·2021-01-26·CVSS 2.5
CVE-2021-3156 [LOW] sudo vulnerabilities
sudo vulnerabilities
It was discovered that Sudo incorrectly handled memory when parsing command
lines. A local attacker could possibly use this issue to obtain unintended
access to the administrator account. (CVE-2021-3156)
It was discovered that the Sudo sudoedit utility incorrectly handled
checking directory permissions. A local attacker could possibly use this
issue to bypass file permissions and determine if a directory exists or
not. (CVE-2021-23239)
OSV
CVE-2021-3156: Sudo before 1
osv·2021-01-26·CVSS 7.8
CVE-2021-3156 [HIGH] CVE-2021-3156: Sudo before 1
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
VulnCheck
Sudo Heap-Based Buffer Overflow Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-3156 [HIGH] CWE-122 Sudo Heap-Based Buffer Overflow Vulnerability
Sudo Heap-Based Buffer Overflow Vulnerability
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
Affected: Sudo Sudo
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cisa.gov/news-events/alerts/2022/04/27/2021-top-routinely-exploited-vulnerabilities; https://cisa.gov/news-events/cybersecurity-advisories/aa22-117a; https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/ex-cobalt-go-red-tehnika-skrytogo-tunnelya/; https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/excobalt-gored-the-hidden-tunnel-technique/; https://securelist.com/vulnerabilities-and-exploits-in-
CISA ICS
Hitachi Energy TXpert Hub CoreTec 4 Sudo Vulnerability
cisa_ics·2022-09-13·CVSS 7.8
[HIGH] Hitachi Energy TXpert Hub CoreTec 4 Sudo Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy TXpert Hub CoreTec 4 Sudo Vulnerability
Last RevisedSeptember 13, 2022
Alert CodeICSA-22-256-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: TXpert Hub CoreTec 4
- Vulnerability: Off-by-one Error
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to take control of the system node and its information.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of TXpert Hub CoreTec 4, a digital transformer monitoring and diagnostics devic
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Sudo) — CVE-2021-3156
vendor_oracle·2022-04-15·CVSS 7.8
CVE-2021-3156 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Sudo) — CVE-2021-3156
Oracle Oracle Communications Risk Matrix: Platform (Sudo) vulnerability
CVE: CVE-2021-3156
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
CISA
Sudo Heap-Based Buffer Overflow Vulnerability
cisa·2022-04-06·CVSS 7.8
CVE-2021-3156 [HIGH] CWE-122 Sudo Heap-Based Buffer Overflow Vulnerability
Vulnerability: Sudo Heap-Based Buffer Overflow Vulnerability
Affected: Sudo Sudo
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-3156
Remediation Due Date: 2022-04-27
CISA ICS
Johnson Controls CEM Systems AC2000
cisa_ics·2021-11-30·CVSS 7.8
[HIGH] Johnson Controls CEM Systems AC2000
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Johnson Controls CEM Systems AC2000
Last RevisedNovember 30, 2021
Alert CodeICSA-21-334-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Controlled Electronic Management Systems, Ltd., a subsidiary of Johnson Controls, Inc.
- Equipment: CEM Systems AC2000
- Vulnerability: Off-by-one Error
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a local attacker to obtain “super user” access on the underlying Linux operating system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Contr
Oracle
Oracle Oracle Communications Risk Matrix: Storage Management (Sudo) — CVE-2021-3156
vendor_oracle·2021-10-15·CVSS 7.8
CVE-2021-3156 [HIGH] Oracle Oracle Communications Risk Matrix: Storage Management (Sudo) — CVE-2021-3156
Oracle Oracle Communications Risk Matrix: Storage Management (Sudo) vulnerability
CVE: CVE-2021-3156
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
CISA ICS
Johnson Controls Sensormatic Electronics Illustra
cisa_ics·2021-09-02·CVSS 7.8
[HIGH] Johnson Controls Sensormatic Electronics Illustra
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Johnson Controls Sensormatic Electronics Illustra
Last RevisedSeptember 02, 2021
Alert CodeICSA-21-245-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Sensormatic Electronics, LLC, a subsidiary of Johnson Controls, Inc.
- Equipment: Illustra
- Vulnerability: Off-by-one Error
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a local attacker to obtain super user access to the underlying Linux operating system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Johnson Controls reports this vulnerability af
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Workstation 310 (Sudo) — CVE-2021-3156
vendor_oracle·2021-07-15·CVSS 7.8
CVE-2021-3156 [HIGH] Oracle Oracle Food and Beverage Applications Risk Matrix: Workstation 310 (Sudo) — CVE-2021-3156
Oracle Oracle Food and Beverage Applications Risk Matrix: Workstation 310 (Sudo) vulnerability
CVE: CVE-2021-3156
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
CISA ICS
Johnson Controls Sensormatic Electronics VideoEdge
cisa_ics·2021-05-27·CVSS 7.8
[HIGH] Johnson Controls Sensormatic Electronics VideoEdge
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Johnson Controls Sensormatic Electronics VideoEdge
Last RevisedMay 27, 2021
Alert CodeICSA-21-147-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Sensormatic Electronics, LLC, a subsidiary of Johnson Controls
- Equipment: VideoEdge
- Vulnerability: Off-by-one Error
## 2. RISK EVALUATION
Under specific circumstances, a local authenticated user may be able to exploit this vulnerability to gain administrative access.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Johnson Controls reports the vulnerability affects the following Sensor
CISA ICS
Johnson Controls Sensormatic Tyco AI
cisa_ics·2021-05-13·CVSS 7.8
[HIGH] Johnson Controls Sensormatic Tyco AI
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Johnson Controls Sensormatic Tyco AI
Last RevisedMay 13, 2021
Alert CodeICSA-21-133-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.0
- Vendor: Sensormatic Electronics, LLC, a subsidiary of Johnson Controls
- Equipment: Tyco AI
- Vulnerability: Off-by-one Error
## 2. RISK EVALUATION
Under specific circumstances, a local attacker could use this vulnerability to obtain super-user access to the underlying openSUSE Linux operating system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Johnson Controls reports this vulnerability affects the following Sensormatic Electronics products
CISA ICS
Johnson Controls Exacq Technologies exacqVision
cisa_ics·2021-04-29·CVSS 7.8
[HIGH] Johnson Controls Exacq Technologies exacqVision
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Johnson Controls Exacq Technologies exacqVision
Last RevisedApril 29, 2021
Alert CodeICSA-21-119-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.0
- Vendor: Exacq Technologies, Inc., a subsidiary of Johnson Controls, Inc.
- Equipment: exacqVision
- Vulnerability: Off-by-one Error
## 2. RISK EVALUATION
A local attacker could exploit this vulnerability to obtain “Super User” access to the underlying Ubuntu Linux operating system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Johnson Controls reports the vulnerability affects the following products running on unpatched versions o
Palo Alto
Informational: Impact of Sudo Vulnerability CVE-2021-3156
vendor_paloalto·2021-02-10·CVSS 7.8
CVE-2021-3156 [HIGH] Informational: Impact of Sudo Vulnerability CVE-2021-3156
Informational: Impact of Sudo Vulnerability CVE-2021-3156
Palo Alto Networks Product Security Assurance team has evaluated the Sudo software vulnerability CVE-2021-3156.
PAN-OS software, Prisma Cloud compute, and Prisma SD-WAN (CloudGenix) devices do not include the Sudo program and, therefore, no scenarios required for successful exploitation exist in these Palo Alto Networks products.
Affected products: PAN-OS, Prisma Cloud Compute, Prisma SD-WAN (CloudGenix)
Solution: No product updates are required for this vulnerability.
Cisco
Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
vendor_cisco·2021-01-29
CVE-2021-3156 [HIGH] CWE-122 Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
A vulnerability in the command line parameter parsing code of Sudo could allow an authenticated, local attacker to execute commands or binaries with root privileges.
The vulnerability is due to improper parsing of command line parameters that may result in a heap-based buffer overflow. An attacker could exploit this vulnerability by accessing a Unix shell on an affected device and then invoking the sudoedit command with crafted parameters or by executing a binary exploit. A successful exploit could allow the attacker to execute commands or binaries with root privileges.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-p
Ubuntu
Sudo vulnerability
vendor_ubuntu·2021-01-27·CVSS 7.8
CVE-2021-3156 [HIGH] Sudo vulnerability
Title: Sudo vulnerability
Summary: Several security issues were fixed in Sudo.
USN-4705-1 fixed a vulnerability in Sudo. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Sudo incorrectly handled memory when parsing command
lines. A local attacker could possibly use this issue to obtain unintended
access to the administrator account. (CVE-2021-3156)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Sudo vulnerabilities
vendor_ubuntu·2021-01-26·CVSS 2.5
CVE-2021-3156 [LOW] Sudo vulnerabilities
Title: Sudo vulnerabilities
Summary: Several security issues were fixed in Sudo.
It was discovered that Sudo incorrectly handled memory when parsing command
lines. A local attacker could possibly use this issue to obtain unintended
access to the administrator account. (CVE-2021-3156)
It was discovered that the Sudo sudoedit utility incorrectly handled
checking directory permissions. A local attacker could possibly use this
issue to bypass file permissions and determine if a directory exists or
not. (CVE-2021-23239)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: Heap buffer overflow in argument parsing
vendor_redhat·2021-01-26·CVSS 7.8
CVE-2021-3156 [HIGH] CWE-122 sudo: Heap buffer overflow in argument parsing
sudo: Heap buffer overflow in argument parsing
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
A flaw was found in sudo. A heap-based buffer overflow was found in the way sudo parses command line arguments. This flaw is exploitable by any local user who can execute the sudo command (by default, any local user can execute sudo) without authentication. Successful exploitation of this flaw could lead to privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This flaw does not affect the versions of sudo shipped with R
Debian
CVE-2021-3156: sudo - Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based...
vendor_debian·2021·CVSS 7.8
CVE-2021-3156 [HIGH] CVE-2021-3156: sudo - Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based...
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Scope: local
bookworm: resolved (fixed in 1.9.5p1-1.1)
bullseye: resolved (fixed in 1.9.5p1-1.1)
forky: resolved (fixed in 1.9.5p1-1.1)
sid: resolved (fixed in 1.9.5p1-1.1)
trixie: resolved (fixed in 1.9.5p1-1.1)
Cisco
Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
vendor_cisco
CVE-2021-3156 Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
CVE-2021-3156: Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
A vulnerability in the command line parameter parsing code of Sudo could allow an authenticated, local attacker to execute commands or binaries with root privileges. The vulnerability is due to improper parsing of command line parameters that may result in a heap-based buffer overflow. An attacker could exploit this vulnerability by accessing a Unix shell on an affected device and then invoking the sudoedit command with crafted parameters or by executing a binary exploit. A successful exploit could allow the attacker to execute commands or binaries with root privileges. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/c
YARA
Linux_Exploit_CVE_2021_3156_7f5672d0
yara·CVSS 7.8
CVE-2021-3156 [HIGH] Linux_Exploit_CVE_2021_3156_7f5672d0
rule Linux_Exploit_CVE_2021_3156_7f5672d0 {
meta:
author = "Elastic Security"
id = "7f5672d0-73f1-4143-b3e2-3aed110779e3"
fingerprint = "71e90dd36342686bb4be7ef86e1ceb2e915c70f437f4733ddcc5175860ca4084"
creation_date = "2021-09-15"
last_modified = "2021-09-21"
threat_name = "Linux.Exploit.CVE-2021-3156"
reference_sample = "1a4517d2582ac97b88ae568c23e75beba93daf8518bd3971985d6a798049fd61"
severity = 100
arch_context = "x86"
scan_context = "file"
license = "Elastic License v2"
os = "linux"
strings:
$a1 = "/tmp/gogogo123456789012345678901234567890go" fullword
$a2 = "gg:$5$a$gemgwVPxLx/tdtByhncd4joKlMRYQ3IVwdoBXPACCL2:0:0:gg:/root:/bin/bash" fullword
$sudo = "sudoedit" fullword
$msg1 = "succes with sleep time %d us" fullword
$msg2 = "[+] Success with %d attempts" fullword
$msg3 = "symlink 2nd
YARA
Linux_Exploit_CVE_2021_3156_f3fb10cd
yara·CVSS 7.8
CVE-2021-3156 [HIGH] Linux_Exploit_CVE_2021_3156_f3fb10cd
rule Linux_Exploit_CVE_2021_3156_f3fb10cd {
meta:
author = "Elastic Security"
id = "f3fb10cd-1d49-420f-8740-5c8990560943"
fingerprint = "66aca7d13fb9c5495f17b7891e388db0a746d8827c8ae302a6cb8d86f7630bbb"
creation_date = "2021-09-15"
last_modified = "2021-09-21"
threat_name = "Linux.Exploit.CVE-2021-3156"
reference_sample = "65fb8baa5ec3bfb4473e4b2f565b461dd59989d43c72b1c5ec2e1a68baa8b51a"
severity = 100
arch_context = "x86"
scan_context = "file"
license = "Elastic License v2"
os = "linux"
strings:
$a1 = "/usr/bin/sudoedit" fullword
$a2 = "" fullword
condition:
all of them
}
Elastic
Deprecated - Sudo Heap-Based Buffer Overflow Attempt
elastic_rules·CVSS 7.8
CVE-2021-3156 [HIGH] Deprecated - Sudo Heap-Based Buffer Overflow Attempt
Deprecated - Sudo Heap-Based Buffer Overflow Attempt
Identifies the attempted use of a heap-based buffer overflow vulnerability for the Sudo binary in Unix-like systems
(CVE-2021-3156). Successful exploitation allows an unprivileged user to escalate to the root user.
Query:
event.category:process and event.type:start and
process.name:(sudo or sudoedit) and
process.args:(*\\ and ("-i" or "-s"))
Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
exploitdb·2021-02-03·CVSS 7.8
CVE-2021-3156 [HIGH] Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
---
# Exploit Title: Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
# Date: 2021-02-02
# Exploit Author: West Shepherd
# Version: Sudo legacy versions from 1.8.2 to 1.8.31p2, stable versions from 1.9.0 to 1.9.5p1.
# Tested on: Ubuntu 20.04.1 LTS Sudo version 1.8.31
# CVE : CVE-2021-3156
# Credit to: Advisory by Baron Samedit of Qualys and Stephen Tong (stong) for the C based exploit code.
# Sources:
# (1) https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
# (2) https://github.com/stong/CVE-2021-3156
# Requirements: Python3
#!/usr/bin/python3
import os
import pwd
import time
import sys
import argpa
Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)
exploitdb·2021-02-03·CVSS 7.8
CVE-2021-3156 [HIGH] Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)
---
# Exploit Title: Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)
# Authors and Contributors: cts, help from r4j, debug by nu11secur1ty
# Date: 30.01.2021
# Vendor: https://www.sudo.ws/
# Link: https://www.sudo.ws/download.html
# CVE: CVE-2021-3156
[+] Source: https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-3156/1.30.2021
[Exploit Program Code]
// Exploit by @gf_256 aka cts
// With help from r4j
// Debug by @nu11secur1ty
// Original advisory by Baron Samedit of Qualys
// Tested on Ubuntu 18.04 and 20.04 & 20.04.01
// You will probably need to adjust RACE_SLEEP_TIME.
#include
#include
#include
#include
#include
#include
#include
#include
#include
#in
Nuclei
Sudo Baron Samedit - Local Privilege Escalation
nuclei·CVSS 7.8
CVE-2021-3156 [HIGH] Sudo Baron Samedit - Local Privilege Escalation
Sudo Baron Samedit - Local Privilege Escalation
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Template:
id: CVE-2021-3156
info:
name: Sudo Baron Samedit - Local Privilege Escalation
author: pussycat0x
severity: high
description: |
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
remediation: |
Upgrade Sudo to version 1.9.5p2 or later that fixes the heap-based buffer overflow vulnerability.
impact: |
Attackers can escalate pri
Metasploit
Sudo Heap-Based Buffer Overflow
metasploit
Sudo Heap-Based Buffer Overflow
Sudo Heap-Based Buffer Overflow
A heap based buffer overflow exists in the sudo command line utility that can be exploited by a local attacker to gain elevated privileges. The vulnerability was introduced in July of 2011 and affects version 1.8.2 through 1.8.31p2 as well as 1.9.0 through 1.9.5p1 in their default configurations. The technique used by this implementation leverages the overflow to overwrite a service_user struct in memory to reference an attacker controlled library which results in it being loaded with the elevated privileges held by sudo.
arXiv
Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host Networks
arxiv_fulltext·2025-11-22
Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host Networks
[0] et al.,
[0] e.g.,
[0] i.e.,
[1] Table
[1] Fig.
[1] Sec.
[1] Appendix
[1] Finding
[0] Incalmo
[0] Incalmo-WHT
[0] Incalmo-WS
[0] MHBench
[0] ExpertPromptShell
Success
TotalAcquisition
Reliability
[1] #1.
[1] #1:
[1] #1
[1]red (vs: #1)
[1]blue (Lujo: #1)
[1]magenta (Brian: #1)
finding
finding[2]
finding
@edef\@currentlabel#1
tcolorbox
Finding #1: #2
tcolorbox
limitation
limitation[2]
limitation
@edef\@currentlabelFailure mode
tcolorbox
#1 (Failure mode ): #2
tcolorbox
.2mm
challenge
challenge[1]
challenge
@edef\@currentlabelname#1
0.2cm
1mm
tcolorbox
Challenge : #1
tcolorbox
.2mm
packeditemizeitemize1
[packeditemize]
label= ,
[1] 0em#10em
[1]
#1
myquote
=0.12in =0.12in
- :
* [1] [baseline=(char.base)]
[shape=circle,text=white,fill=black,draw,inner sep=1pt]
arXiv
Cybersecurity AI Benchmark (CAIBench): A Meta-Benchmark for Evaluating Cybersecurity AI Agents
arxiv_fulltext·2025-10-28
Cybersecurity AI Benchmark (CAIBench): A Meta-Benchmark for Evaluating Cybersecurity AI Agents
-1em
## Abstract
Cybersecurity spans multiple interconnected domains, complicating the development of meaningful, labor-relevant benchmarks. Existing benchmarks assess isolated skills rather than integrated performance. We find that pre-trained knowledge of cybersecurity in LLMs does not imply attack and defense abilities, revealing a gap between knowledge and capability. To address this limitation, we present the Cybersecurity AI Benchmark (CAIBench), a modular meta-benchmark framework that allows evaluating LLM models and agents across offensive and defensive cybersecurity domains, taking a step towards meaningfully measuring their labor-relevance. CAIBench integrates five evaluation categories, covering over 10,000 instances: Jeopardy-style CTFs, Attack and Defense CTFs, Cyber Range e
arXiv
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
arxiv_fulltext·2025-08-21
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
@IEEEauthorhalign
@IEEEauthorhalign
Sabine Houy
Ume University
[email protected]
Bruno Kreyssig
Ume University
[email protected]
Timoth\'ee Riom
Ume University
[email protected]
Alexandre Bartel
Ume University
[email protected]
Patrick McDaniel
University of Wisconsin-Madison
[email protected]
## Abstract
Memory corruption vulnerabilities remain one of the most severe threats to software security. They often allow attackers to achieve arbitrary code execution by redirecting a vulnerable program's control flow.
While Control Flow Integrity (CFI) has gained traction to mitigate this exploitation path, developers are not provided with any direction on how to apply CFI to real-world software.
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects
arxiv_fulltext·2024-08-19
Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects
Top of the Heap: Efficient Memory Error Protection
of Safe Heap Objects
0
@IEEEauthorhalign
@IEEEauthorhalign
Kaiming Huang
Penn State University
[email protected]
Mathias Payer
EPFL
[email protected]
Zhiyun Qian
UC Riverside
[email protected]
Jack Sampson
Penn State University
[email protected]
\ \ \ \ Gang Tan
\ \ \ \ Penn State University
\ \ \ \ [email protected]
Trent Jaeger
Penn State University
[email protected]
Kaiming Huang
Penn State University
[email protected]
Mathias Payer
EPFL
[email protected]
Zhiyun Qian
UC Riverside
[email protected]
Jack Sampson
Penn State University
[email protected]
Gang Tan
Penn State University
[email protected]
Trent Jaeger
UC Riverside
[email protected]
0
CCSXML
10002978.10003022.10003023
Security and privacy Software
arXiv
URSID: Using formalism to Refine attack Scenarios for vulnerable Infrastructure Deployment
arxiv_fulltext·2023-03-30
URSID: Using formalism to Refine attack Scenarios for vulnerable Infrastructure Deployment
URSID: Using formalism to Refine attack Scenarios for vulnerable Infrastructure Deployment
Pierre-Victor Besson
CentraleSupélec, Inria, univ. Rennes, CNRS, IRISA
Rennes
France
[email protected]
Valerie Viet Triem Tong
CentraleSupélec, Inria, univ. Rennes, CNRS, IRISA
Rennes
France
[email protected]
Gilles Guette
univ. Rennes, CNRS, Inria, IRISA
Rennes
France
[email protected]
Guillaume Piolle
Thales
Rennes
France
[email protected]
Erwan Abgrall
CentraleSupélec, Inria
Rennes
France
[email protected]
Besson et al.
## Abstract
In this paper we propose a novel way of deploying vulnerable architectures for defense and research purposes, which aims to generate deception platforms based on the formal descript
CTF
cheatsheets / privesc-linux
ctf_writeups
cheatsheets / privesc-linux
---
layout: default
title: "Linux Privesc"
parent: Cheatsheets
grand_parent: Resources
nav_order: 3
permalink: /resources/cheatsheets/privesc-linux/
---
# Linux Privilege Escalation Cheatsheet
Common privesc vectors encountered in HTB machines.
## Quick Wins
```bash
# 1. Sudo misconfiguration
sudo -l
# Check GTFOBins for any allowed binary
# 2. SUID binaries
find / -perm -4000 -type f 2>/dev/null
# Check GTFOBins for any unusual SUID binary
# 3. Writable /etc/passwd
ls -la /etc/passwd
# If writable, add a root user:
echo 'hacker:$1$hacker$TzyKlv0/R/c28R.GAeLw.1:0:0:Hacker:/root:/bin/bash' >> /etc/passwd
# 4. Readable /etc/shadow
ls -la /etc/shadow
# Copy hashes, crack with hashcat/john
# 5. SSH keys
cat /root/.ssh/id_rsa
cat /home/*/.ssh/id_rsa
find / -name "id_rsa" 2>/dev/null
```
CTF
RouterSpace / README
ctf_writeups·CVSS 7.8
[HIGH] RouterSpace / README
# RouterSpace - HackTheBox - Writeup
Linux, 20 Base Points, Easy
## Machine
## TL;DR
To solve this machine, we begin by enumerating open services using ```namp``` – finding ports ```22``` and ```80```.
***User***: By analyzing the ```RouterSpace.apk``` application we found an HTTP POST request to ```routerspace.htb/api/v4/monitoring/router/dev/check/deviceAccess``` which is vulnerable to command injection, Using that we add our SSH public key and we get a shell as ```paul``` user.
***Root***: By checking the ```sudo``` version we can see the ```sudo``` is vulnerable to ```CVE-2021-3156```, Using that we get the ```root``` flag.
## RouterSpace Solution
### User
Let's start with ```nmap``` scanning:
```console
┌─[evyatar@parrot]─[/hackthebox/RouterSpace]
└──╼ $ nmap -sV -sC -oA
CTF
Paper / README
ctf_writeups
Paper / README
# Paper
> Write-up author: jon-brandy
## STEPS:
> PORT SCANNING
```
┌──(brandy㉿bread-yolk)-[~]
└─$ nmap -p- -sVC 10.10.11.143 --min-rate 1000
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-22 20:39 PDT
Nmap scan report for 10.10.11.143
Host is up (0.077s latency).
Not shown: 64783 closed tcp ports (conn-refused), 749 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.0 (protocol 2.0)
| ssh-hostkey:
| 2048 1005ea5056a600cb1c9c93df5f83e064 (RSA)
| 256 588c821cc6632a83875c2f2b4f4dc379 (ECDSA)
|_ 256 3178afd13bc42e9d604eeb5d03eca022 (ED25519)
80/tcp open http Apache httpd 2.4.37 ((centos) OpenSSL/1.1.1k mod_fcgid/2.3.9)
|_http-generator: HTML Tidy for HTML5 for Linux version 5.7.28
| http-methods:
|_ Potentially risky methods: TRACE
|_http-title: HTTP
Qualys
Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
## Table of Contents
Introduction
Why This Matters Now
Looking Back: The Original Discovery
Guidance for Security Teams
A Note on Our Research Mission
Conclusion
Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog . The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers . In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this vulnera
Qualys
Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
#### Table of Contents
- Introduction
- Why This Matters Now
- Looking Back: The Original Discovery
- Guidance for Security Teams
- A Note on Our Research Mission
- Conclusion
- Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog. The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers. In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this
Unit42
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
blogs_unit42·2025-07-29
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
## Executive Summary
Unit 42 has observed multiple incidents targeting the telecommunications industry in Southwest Asia. We are currently tracking this activity as CL-STA-0969. This activity includes attacking and leveraging interconnected mobile roaming networks. This report provides a technical analysis of the activity cluster based on our incident response engagements including observed tactics, techniques and procedures (TTPs).
We found no clear evidence of data collection or exfiltration from the investigated systems and networks, nor any attempts to track or communicate with target devices within mobile networks. However, the threat actor behind CL-STA-0969 maintained high operational security (OPSEC) and employed various defense evasion techniques to avoid detection.
The actors
Unit42
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
blogs_unit42·2025-07-29
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
## The Covert Operator's Playbook: Infiltration of Global Telecom Networks
Renzon Cruz
Nicolas Bareil
Navin Thomas
Published: July 29, 2025
Malware
Threat Actor Groups
Threat Research
Vulnerabilities
Advanced Persistent Threat
Backdoor
CL-STA-0969
GALLIUM
GoLang
Liminal Panda
PingPull
Telecoms
UNC1945
UNC2891
UNC3886
## Executive Summary
Unit 42 has observed multiple incidents targeting the telecommunications industry in Southwest Asia. We are currently tracking this activity as CL-STA-0969 . This activity includes attacking and leveraging interconnected mobile roaming networks. This report provides a technical analysis of the activity cluster based on our incident response engagements including observed tactics, techniques and procedures (TTPs).
We found no clear
Securelist
Vulnerability landscape analysis for Q1 2025
blogs_securelist·2025-05-30
Vulnerability landscape analysis for Q1 2025
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- Interesting vulnerabilities
- Conclusion and advice
Authors
- Alexander Kolesnikov
The first quarter of 2025 saw the continued publication of vulnerabilities discovered and fixed in 2024, as some researchers were previously unable to disclose the details. This partially shifted the focus away from vulnerabilities that received new CVE-2025-NNNNN identifiers. The nature of the CVE assignment process can result in a notable delay between problem investigation and patch release, which is mitigated by reserving a CVE ID early in the process. As for trends in vulnerability exploitation, we are seeing increasing rates of attacks targeting older operating syste
Trailofbits
cURL audit: How a joke led to significant findings
blogs_trailofbits·2023-02-14·CVSS 8.1
CVE-2022-42915 [HIGH] cURL audit: How a joke led to significant findings
In fall 2022, Trail of Bits audited cURL, a widely-used command-line utility that transfers data between a server and supports various protocols. The project coincided with a Trail of Bits maker week, which meant that we had more manpower than we usually do, allowing us to take a nonstandard approach to the audit.
curl AAAAAAAAAA…
CVE-2022-42915 – Double free when using HTTP proxy with specific protocols. Fixed in cURL 7.86.0
CVE-2022-43552 – Use-after-free when HTTP proxy denies tunneling SMB/TELNET protocols. Fixed in cURL 7.87.0
TOB-CURL-10 – Use-after-free while using parallel option and sequences. Fixed in cURL 7.86.0
TOB-CURL-11 – Unused memory blocks are not freed, resulting in memory leaks. Fixed in cURL 7.87.0
## Working with cURL
curl-fuzzer
AddressSanitizer
main()
argc
Trailofbits
cURL audit: How a joke led to significant findings
blogs_trailofbits·2023-02-14·CVSS 8.1
[HIGH] cURL audit: How a joke led to significant findings
In fall 2022, Trail of Bits audited cURL, a widely-used command-line utility that transfers data between a server and supports various protocols. The project coincided with a Trail of Bits maker week, which meant that we had more manpower than we usually do, allowing us to take a nonstandard approach to the audit.
While discussing the threat model of the application, one of our team members jokingly asked, “Have we tried `curl AAAAAAAAAA…` yet”? Although the comment was made in jest, it sparked an idea: we should fuzz cURL’s command-line interface (CLI). Once we did so, the fuzzer quickly uncovered memory corruption bugs, specifically use-after-free issues, double-free issues, and memory leaks. Because the bugs are in libcurl, a cURL development library, they have the potential to affect
Wiz
Recent Linux sudo vulnerability affects a major percent of cloud workloads | Wiz Blog
blogs_wiz·2021-02-02·CVSS 7.8
CVE-2021-3156 [HIGH] Recent Linux sudo vulnerability affects a major percent of cloud workloads | Wiz Blog
## What happened?
A newly discovered high severity vulnerability (CVE-2021-3156) in the sudo package allows privilege escalation from any user to root without any authentication. The package sudo is a near universal utility across Linux distributions and flavors that manages local user privileges. Therefore, this vulnerability presents a major and immediate risk. The affected versions are all legacy versions from 1.8.2 to 1.8.31p2 and all stable versions from 1.9.0 to 1.9.5p1 in their default configuration.
## Impact
With an estimated 90% of cloud workloads running Linux based OS, with sudo being common across distributions, many Linux cloud assets are at risk and may be affected. Versions released as far back as 2011 are affected by this vulnerability.
Affected versions of sudo:
- Al
Wiz
Recent Linux sudo vulnerability affects a major percent of cloud workloads | Wiz Blog
blogs_wiz·2021-02-02·CVSS 7.8
CVE-2021-3156 [HIGH] Recent Linux sudo vulnerability affects a major percent of cloud workloads | Wiz Blog
## What happened?
A newly discovered high severity vulnerability (CVE-2021-3156) in the sudo package allows privilege escalation from any user to root without any authentication. The package sudo is a near universal utility across Linux distributions and flavors that manages local user privileges. Therefore, this vulnerability presents a major and immediate risk. The affected versions are all legacy versions from 1.8.2 to 1.8.31p2 and all stable versions from 1.9.0 to 1.9.5p1 in their default configuration.
## Impact
With an estimated 90% of cloud workloads running Linux based OS, with sudo being common across distributions, many Linux cloud assets are at risk and may be affected. Versions released as far back as 2011 are affected by this vulnerability.
Affected versions of sudo:
All
Checkpoint
1st February – Threat Intelligence Report
blogs_checkpoint·2021-02-01·CVSS 9.1
CVE-2012-3152 [CRITICAL] 1st February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st February, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Europol and law enforcement agencies from eight countries have partnered in a joint operation in order to takedown the attack infrastructure of Emotet, the most prominent botnet distributed to-date. Authorities plan to uninstall the malware from victim machines on April 25, 2021.
Check Point SandBlast and Anti-Bot pr
Qualys
Sudo Vulnerability CVE-2021-3156: Root Access Risk | Qualys
blogs_qualys·2021-01-26·CVSS 7.8
CVE-2021-3156 [HIGH] Sudo Vulnerability CVE-2021-3156: Root Access Risk | Qualys
#### Table of Contents
- Disclosure Timeline of the Sudo Vulnerability (CVE-2021-3156)
- Watch the Sudo Exploit Proof of Concept Video
- Technical Analysis of Sudo Vulnerability
- Solution: Fix with Qualys VMDR
- Qualys Coverage: Detecting the Sudo Vulnerability
- VMDR Dashboard Qualys
- Vendor References
- Frequently Asked Questions (FAQs)
Update Feb 3, 2021: It has been reported that macOS, AIX, and
Solaris are also vulnerable to CVE-2021-3156, and that others may also
still be vulnerable. Qualys has not independently verified the exploit.
Original Post: The Qualys Research Team has discovered a heap overflow vulnerability in sudo, a near-ubiquitous utility available on major Unix-like operating systems. Any unprivileged user can gain root privileges on a vulnerable host using a defau
Qualys
CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
blogs_qualys·2021-01-26·CVSS 7.8
CVE-2021-3156 [HIGH] CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
## Table of Contents
Disclosure Timeline of the Sudo Vulnerability (CVE-2021-3156)
Watch the Sudo Exploit Proof of Concept Video
Technical Analysis of Sudo Vulnerability
Solution: Fix with Qualys VMDR
Qualys Coverage: Detecting the Sudo Vulnerability
VMDR Dashboard Qualys
Vendor References
Frequently Asked Questions (FAQs)
Update Feb 3, 2021 : It has been reported that macOS, AIX, and Solaris are also vulnerable to CVE-2021-3156, and that others may also still be vulnerable. Qualys has not independently verified the exploit.
Original Post : The Qualys Research Team has discovered a heap overflow vulnerability in sudo, a near-ubiquitous utility available on major Unix-like operating systems. Any unprivileged user can gain root privileges on a vulnerable host using a default sudo c
Crowdstrike
How Falcon Spotlight Helps Detect CVE-2021-3156 Vulnerabilities
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] How Falcon Spotlight Helps Detect CVE-2021-3156 Vulnerabilities
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
How Falcon Spotlight Helps Detect CVE-2021-3156 Vulnerabilities
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] How Falcon Spotlight Helps Detect CVE-2021-3156 Vulnerabilities
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Huntress
CVE-2021-3156 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 7.8
CVE-2021-3156 [HIGH] CVE-2021-3156 Vulnerability: Analysis, Impact, Mitigation | Huntress
## CVE-2021-3156 Vulnerability
Published: 11/21/2025
Written by: Lizzie Danielson
## What is CVE-2021-3156 vulnerability?
CVE-2021-3156, commonly referred to as "Baron Samedit," is a heap-based buffer overflow vulnerability in the sudo command—a widely used utility in UNIX and Linux systems. This vulnerability allows local attackers to gain unauthorized root-level access without authentication. It is classified as a privilege escalation vulnerability and has a high severity due to its widespread applicability and critical impact.
## When was it discovered?
CVE-2021-3156 was disclosed on January 26, 2021, by researchers at Qualys . The vulnerability affected multiple versions of the sudo utility and had likely remained exploitable for years before discovery. The disclosure timeline in
http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2021/Feb/42http://seclists.org/fulldisclosure/2021/Jan/79http://seclists.org/fulldisclosure/2024/Feb/3http://www.openwall.com/lists/oss-security/2021/01/26/3http://www.openwall.com/lists/oss-security/2021/01/27/1http://www.openwall.com/lists/oss-security/2021/01/27/2http://www.openwall.com/lists/oss-security/2021/02/15/1http://www.openwall.com/lists/oss-security/2021/09/14/2http://www.openwall.com/lists/oss-security/2024/01/30/6http://www.openwall.com/lists/oss-security/2024/01/30/8https://kc.mcafee.com/corporate/index?page=content&id=SB10348https://lists.debian.org/debian-lts-announce/2021/01/msg00022.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/https://security.gentoo.org/glsa/202101-33https://security.netapp.com/advisory/ntap-20210128-0001/https://security.netapp.com/advisory/ntap-20210128-0002/https://support.apple.com/kb/HT212177https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcMhttps://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerabilityhttps://www.debian.org/security/2021/dsa-4839https://www.kb.cert.org/vuls/id/794544https://www.openwall.com/lists/oss-security/2021/01/26/3https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.sudo.ws/stable.html#1.9.5p2https://www.synology.com/security/advisory/Synology_SA_21_02https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2021/Feb/42http://seclists.org/fulldisclosure/2021/Jan/79http://seclists.org/fulldisclosure/2024/Feb/3http://www.openwall.com/lists/oss-security/2021/01/26/3http://www.openwall.com/lists/oss-security/2021/01/27/1http://www.openwall.com/lists/oss-security/2021/01/27/2http://www.openwall.com/lists/oss-security/2021/02/15/1http://www.openwall.com/lists/oss-security/2021/09/14/2http://www.openwall.com/lists/oss-security/2024/01/30/6http://www.openwall.com/lists/oss-security/2024/01/30/8https://kc.mcafee.com/corporate/index?page=content&id=SB10348https://lists.debian.org/debian-lts-announce/2021/01/msg00022.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/https://security.gentoo.org/glsa/202101-33https://security.netapp.com/advisory/ntap-20210128-0001/https://security.netapp.com/advisory/ntap-20210128-0002/https://support.apple.com/kb/HT212177https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcMhttps://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerabilityhttps://www.debian.org/security/2021/dsa-4839https://www.kb.cert.org/vuls/id/794544https://www.openwall.com/lists/oss-security/2021/01/26/3https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.sudo.ws/stable.html#1.9.5p2https://www.synology.com/security/advisory/Synology_SA_21_02https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3156
2021-01-26
Published
2022-04-06
Added to CISA KEV
Exploited in the wild