CVE-2016-3643

HIGH KEV

SolarWinds Virtualization Manager <6.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-3643 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 1 public exploit from researchers including Nate Kettlewell.

AI-analyzed exploit summary The exploit details a sudo misconfiguration in Solarwinds Virtualization Manager, allowing any local user to execute commands as root. The PoC demonstrates reading /etc/passwd using sudo, highlighting a privilege escalation vulnerability.

Description

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

Exploits (1)

exploitdb WRITEUP
by Nate Kettlewell · textlocallinux
https://www.exploit-db.com/exploits/39967

The exploit details a sudo misconfiguration in Solarwinds Virtualization Manager, allowing any local user to execute commands as root. The PoC demonstrates reading /etc/passwd using sudo, highlighting a privilege escalation vulnerability.

Classification
Writeup 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Solarwinds Virtualization Manager < 6.3.1
Auth required
Prerequisites: Local shell access on the vulnerable appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/39967/
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Jun/26

Scores

CVSS v3 7.8
EPSS 0.0370
EPSS Percentile 88.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2016-4668
CWE
CWE-264
Status published
Products (1)
solarwinds/virtualization_manager < 6.3.1
Published Jun 17, 2016
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026