CVE-2016-3643

HIGH KEV

SolarWinds Virtualization Manager <6.3.1 - Privilege Escalation

Title source: llm

Description

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

Exploits (1)

exploitdb WRITEUP
by Nate Kettlewell · textlocallinux
https://www.exploit-db.com/exploits/39967

Scores

CVSS v3 7.8
EPSS 0.0518
EPSS Percentile 89.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2016-4668
CWE
CWE-264
Status published
Products (1)
solarwinds/virtualization_manager < 6.3.1
Published Jun 17, 2016
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026