Skip to main content

CVE detail

CVE-2021-3156

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVSS 7.8 · HighBuzz score 89.3KEV listed3 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 89.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 15.4
Mention score
28.9
17 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
15.4
3 repos · best confidence 0.99
Best PoC traction
2
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
3
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
17 source links · newest first
  • ed inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit ( CVE-2021-4034 ), the sudo heap overflow ( CVE-2021-3156 ), and the long-standing IIS WebDAV vulnerability ( CVE-2017-7269 ). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems en

    newssecurityaffairs.comJul 24, 2026, 12:10 PM
  • QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P

    vendorblog.qualys.comJul 14, 2026, 6:00 PM
  • QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P

    vendorblog.qualys.comJul 8, 2026, 10:15 PM
  • State-backed group CL-STA-0969 hit Southeast Asian telecoms in 2024, targeting critical infrastructure, says Palo Alto Networks’ Unit 42. Palo Alto Networks reported that a nation-state actor, tracked as CL-STA-0969, targeted telecom firms in Southeast Asia, with attacks on critical infrastructure from February to November 2024. Threat actor CL-STA-0969 overlaps with the China-linked cyber espionage group […]

    newssecurityaffairs.comAug 4, 2025, 7:29 AM
  • Recent activity targeting telecom infrastructure is assessed with high confidence to overlap with Liminal Panda activity. The actors used custom tools, tunneling and OPSEC tactics for stealth.

    vendorunit42.paloaltonetworks.comJul 29, 2025, 9:00 PM
  • The cybercrime group ExCobalt targeted Russian organizations in multiple sectors with a previously unknown backdoor known as GoRed. Positive Technologies researchers reported that a cybercrime gang called ExCobalt targeted Russian organizations in multiple sectors with a previously unknown Golang-based backdoor known as GoRed. Members of the ExCobalt group have been active since at least 2016, […]

    newssecurityaffairs.comJun 24, 2024, 7:36 AM
  • Overview A common attack path that Horizon3 has identified across many of its customers is abusing access to the VMware vCenter Identity Provider (IdP) certificate. Security Assertion Markup Language (SAML) has proved to be a hotbed of vulnerabilities within the last year, as well as a target of many cybercrime syndicates and APTs. In the […]

    exploithorizon3.aiOct 4, 2021, 5:20 PM
  • Hewlett Packard Enterprise (HPE) warns of a vulnerability in Sudo open-source program used in its Aruba AirWave management platform. Hewlett Packard Enterprise (HPE) is warning of a high-severity privilege escalation vulnerability in Sudo open-source program used within its Aruba AirWave management platform. The Aruba AirWave management platform is a real-time monitoring and security alert platform designed by […]

    newssecurityaffairs.comAug 31, 2021, 2:48 PM
  • Apple on Tuesday released macOS security updates to patch a recently disclosed vulnerability in the Sudo utility. Present in most Unix- and Linux-based operating systems out there, Sudo is a tool that allows users to execute programs with the privileges of another user, which by default is superuser.

    newswww.securityweek.comFeb 10, 2021, 3:07 PM
  • Security Affairs newsletter Round 300Security Affairs

    A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the international press subscribe here. Experts explain how to bypass recent improvement of Chinas Great Firewall New Pro-Ocean crypto-miner targets Apache ActiveMQ, Oracle […]

    newssecurityaffairs.comFeb 7, 2021, 11:55 AM
  • Apple’s macOS Big Sur operating system and multiple Cisco products are also affected by the recently disclosed major security flaw in the Sudo utility.

    newswww.securityweek.comFeb 3, 2021, 6:42 PM
  • Experts warn that the recently discovered heap-based buffer overflow bug in Linux SUDO also impacts the latest version of Apple macOS Big Sur. Recently Qualys researchers found a Sudo vulnerability, tracked as CVE-2021-3156, that has allowed any local user to gain root privileges on Unix-like operating systems without authentication. Sudo is one of the most important, powerful, […]

    newssecurityaffairs.comFeb 3, 2021, 4:57 PM
  • 1st February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 1st February, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Europol and law enforcement agencies from eight countries have partnered in a joint operation in order to takedown the attack infrastructure of Emotet, the most prominent botnet distributed to-date. Authorities plan […]

    vendorresearch.checkpoint.comFeb 1, 2021, 3:45 PM
  • Here’s an overview of some of last week’s most interesting news and articles: “Serious” vulnerability found in Libgcrypt, GnuPG’s cryptographic library Libgcrypt 1.9.0, the newest version of a cryptographic library integrated in the GNU Privacy Guard (GnuPG) free encryption software, has a “severe” security vulnerability and should not be used, warned Werner Koch. Apple fixes three actively exploited iOS zero-days Apple has release a new batch of security updates and has fixed three iOS zero-days … More →

    newswww.helpnetsecurity.comJan 31, 2021, 8:55 AM
  • A major security hole in the Sudo utility could be abused by unprivileged users to gain root privileges on the vulnerable host, Qualys reports.

    newswww.securityweek.comJan 27, 2021, 8:30 PM
  • A vulnerability (CVE-2021-3156) in sudo, a powerful and near-ubiquitous open-source utility used on major Linux and Unix-like operating systems, could allow any unprivileged local user to gain root privileges on a vulnerable host (without authentication). “This vulnerability is perhaps the most significant sudo vulnerability in recent memory (both in terms of scope and impact) and has been hiding in plain sight for nearly 10 years,” said Mehul Revankar, Vice President Product Management and Engineering, Qualys, … More →

    newswww.helpnetsecurity.comJan 27, 2021, 9:53 AM
  • CVE-2021-3156 Sudo vulnerability has allowed any local user to gain root privileges on Unix-like operating systems without authentication. Sudo is one of the most important, powerful, and commonly used utilities that comes as a core command pre-installed on macOS and almost every UNIX or Linux-based operating system. sudo is a program for Unix-like computer operating systems that allows […]

    newssecurityaffairs.comJan 27, 2021, 9:13 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

3 repository references · best confidence 0.99 · max 2 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence