CVE detail
CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 15.4
Why it matters now
Mention timeline
- Total mentions
- 3
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
17 source links · newest first
- Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedSecurity Affairs
ed inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit ( CVE-2021-4034 ), the sudo heap overflow ( CVE-2021-3156 ), and the long-standing IIS WebDAV vulnerability ( CVE-2017-7269 ). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems en
newssecurityaffairs.comJul 24, 2026, 12:10 PM QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P
vendorblog.qualys.comJul 14, 2026, 6:00 PM- When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed FirstQualys
QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P
vendorblog.qualys.comJul 8, 2026, 10:15 PM State-backed group CL-STA-0969 hit Southeast Asian telecoms in 2024, targeting critical infrastructure, says Palo Alto Networks’ Unit 42. Palo Alto Networks reported that a nation-state actor, tracked as CL-STA-0969, targeted telecom firms in Southeast Asia, with attacks on critical infrastructure from February to November 2024. Threat actor CL-STA-0969 overlaps with the China-linked cyber espionage group […]
newssecurityaffairs.comAug 4, 2025, 7:29 AMRecent activity targeting telecom infrastructure is assessed with high confidence to overlap with Liminal Panda activity. The actors used custom tools, tunneling and OPSEC tactics for stealth.
vendorunit42.paloaltonetworks.comJul 29, 2025, 9:00 PMThe cybercrime group ExCobalt targeted Russian organizations in multiple sectors with a previously unknown backdoor known as GoRed. Positive Technologies researchers reported that a cybercrime gang called ExCobalt targeted Russian organizations in multiple sectors with a previously unknown Golang-based backdoor known as GoRed. Members of the ExCobalt group have been active since at least 2016, […]
newssecurityaffairs.comJun 24, 2024, 7:36 AM- Compromising vCenter via SAML CertificatesHorizon3.ai
Overview A common attack path that Horizon3 has identified across many of its customers is abusing access to the VMware vCenter Identity Provider (IdP) certificate. Security Assertion Markup Language (SAML) has proved to be a hotbed of vulnerabilities within the last year, as well as a target of many cybercrime syndicates and APTs. In the […]
exploithorizon3.aiOct 4, 2021, 5:20 PM Hewlett Packard Enterprise (HPE) warns of a vulnerability in Sudo open-source program used in its Aruba AirWave management platform. Hewlett Packard Enterprise (HPE) is warning of a high-severity privilege escalation vulnerability in Sudo open-source program used within its Aruba AirWave management platform. The Aruba AirWave management platform is a real-time monitoring and security alert platform designed by […]
newssecurityaffairs.comAug 31, 2021, 2:48 PM- Apple Patches Recent Sudo Vulnerability in macOSSecurityWeek
Apple on Tuesday released macOS security updates to patch a recently disclosed vulnerability in the Sudo utility. Present in most Unix- and Linux-based operating systems out there, Sudo is a tool that allows users to execute programs with the privileges of another user, which by default is superuser.
newswww.securityweek.comFeb 10, 2021, 3:07 PM - Security Affairs newsletter Round 300Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the international press subscribe here. Experts explain how to bypass recent improvement of Chinas Great Firewall New Pro-Ocean crypto-miner targets Apache ActiveMQ, Oracle […]
newssecurityaffairs.comFeb 7, 2021, 11:55 AM Apple’s macOS Big Sur operating system and multiple Cisco products are also affected by the recently disclosed major security flaw in the Sudo utility.
newswww.securityweek.comFeb 3, 2021, 6:42 PMExperts warn that the recently discovered heap-based buffer overflow bug in Linux SUDO also impacts the latest version of Apple macOS Big Sur. Recently Qualys researchers found a Sudo vulnerability, tracked as CVE-2021-3156, that has allowed any local user to gain root privileges on Unix-like operating systems without authentication. Sudo is one of the most important, powerful, […]
newssecurityaffairs.comFeb 3, 2021, 4:57 PM- 1st February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 1st February, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Europol and law enforcement agencies from eight countries have partnered in a joint operation in order to takedown the attack infrastructure of Emotet, the most prominent botnet distributed to-date. Authorities plan […]
vendorresearch.checkpoint.comFeb 1, 2021, 3:45 PM - Week in review: Sudo vulnerability, Emotet takedown, execs targeted with Office 365 phishingHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: “Serious” vulnerability found in Libgcrypt, GnuPG’s cryptographic library Libgcrypt 1.9.0, the newest version of a cryptographic library integrated in the GNU Privacy Guard (GnuPG) free encryption software, has a “severe” security vulnerability and should not be used, warned Werner Koch. Apple fixes three actively exploited iOS zero-days Apple has release a new batch of security updates and has fixed three iOS zero-days … More →
newswww.helpnetsecurity.comJan 31, 2021, 8:55 AM A major security hole in the Sudo utility could be abused by unprivileged users to gain root privileges on the vulnerable host, Qualys reports.
newswww.securityweek.comJan 27, 2021, 8:30 PM- Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156)Help Net Security
A vulnerability (CVE-2021-3156) in sudo, a powerful and near-ubiquitous open-source utility used on major Linux and Unix-like operating systems, could allow any unprivileged local user to gain root privileges on a vulnerable host (without authentication). “This vulnerability is perhaps the most significant sudo vulnerability in recent memory (both in terms of scope and impact) and has been hiding in plain sight for nearly 10 years,” said Mehul Revankar, Vice President Product Management and Engineering, Qualys, … More →
newswww.helpnetsecurity.comJan 27, 2021, 9:53 AM CVE-2021-3156 Sudo vulnerability has allowed any local user to gain root privileges on Unix-like operating systems without authentication. Sudo is one of the most important, powerful, and commonly used utilities that comes as a core command pre-installed on macOS and almost every UNIX or Linux-based operating system. sudo is a program for Unix-like computer operating systems that allows […]
newssecurityaffairs.comJan 27, 2021, 9:13 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
3 repository references · best confidence 0.99 · max 2 stars
- hackingyseguridad/rootHigh confidencegithubRepository topic discovery2 starsDiscovered Jul 12, 2026, 10:50 PM
- TheLeopard65/CVE-2021-3156-Baron-SameditHigh confidencegithubDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 5:43 AM
- Kranti08/CVE-2021-3156-Baron-SameditMedium confidencegithubDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 5:43 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2019-9518CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and…
- CVE-2019-9517CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer ca…
- CVE-2019-9516CVSS 6.5 · Medium
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-l…
- CVE-2019-9515CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the R…
- CVE-2019-9513CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles th…
- CVE-2019-9511CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a…