CVE-2021-3156

HIGH KEV NUCLEI

Sudo Heap-Based Buffer Overflow

Title source: metasploit

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Exploits (98)

nomisec WORKING POC 1,003 stars
by blasty · local
https://github.com/blasty/CVE-2021-3156
nomisec WORKING POC 794 stars
by worawit · local
https://github.com/worawit/CVE-2021-3156
github WORKING POC 690 stars
by lockedbyte · cpoc
https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2021-3156
nomisec WORKING POC 434 stars
by stong · local
https://github.com/stong/CVE-2021-3156
nomisec WRITEUP 225 stars
by LiveOverflow · poc
https://github.com/LiveOverflow/pwnedit
nomisec WORKING POC 203 stars
by Rvn0xsy · local
https://github.com/Rvn0xsy/CVE-2021-3156-plus
nomisec WORKING POC 156 stars
by CptGibbon · local
https://github.com/CptGibbon/CVE-2021-3156
nomisec WORKING POC 111 stars
by reverse-ex · poc
https://github.com/reverse-ex/CVE-2021-3156
nomisec WORKING POC 99 stars
by 0x4ndy · poc
https://github.com/0x4ndy/clif
nomisec WORKING POC 51 stars
by 0xdevil · local
https://github.com/0xdevil/CVE-2021-3156
nomisec WRITEUP 39 stars
by mbcrump · local
https://github.com/mbcrump/CVE-2021-3156
nomisec NO CODE 35 stars
by mr-r3b00t · poc
https://github.com/mr-r3b00t/CVE-2021-3156
nomisec WORKING POC 29 stars
by PhuketIsland · local
https://github.com/PhuketIsland/CVE-2021-3156-centos7
github WORKING POC 20 stars
by flex0geek · cpoc
https://github.com/flex0geek/cves-exploits/tree/main/CVE-2021-3156
nomisec WORKING POC 18 stars
by kernelzeroday · poc
https://github.com/kernelzeroday/CVE-2021-3156-Baron-Samedit
nomisec WORKING POC 16 stars
by jm33-m0 · local
https://github.com/jm33-m0/CVE-2021-3156
nomisec WORKING POC 15 stars
by redhawkeye · poc
https://github.com/redhawkeye/sudo-exploit
nomisec WORKING POC 10 stars
by chenaotian · local
https://github.com/chenaotian/CVE-2021-3156
github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/linux/CVE-2021-3156
nomisec WORKING POC 8 stars
by teamtopkarl · local
https://github.com/teamtopkarl/CVE-2021-3156
nomisec WORKING POC 7 stars
by apogiatzis · poc
https://github.com/apogiatzis/docker-CVE-2021-3156
nomisec WORKING POC 6 stars
by PurpleOzone · local
https://github.com/PurpleOzone/PE_CVE-CVE-2021-3156
nomisec WORKING POC 6 stars
by Mhackiori · local
https://github.com/Mhackiori/CVE-2021-3156
nomisec WORKING POC 6 stars
by Maalfer · local
https://github.com/Maalfer/Sudo-CVE-2021-3156
nomisec SCANNER 5 stars
by yaunsky · poc
https://github.com/yaunsky/cve-2021-3156
nomisec WORKING POC 5 stars
by 1N53C · local
https://github.com/1N53C/CVE-2021-3156-PoC
nomisec WORKING POC 5 stars
by dinhbaouit · local
https://github.com/dinhbaouit/CVE-2021-3156
nomisec WORKING POC 4 stars
by lmol · local
https://github.com/lmol/CVE-2021-3156
nomisec WRITEUP 4 stars
by baka9moe · poc
https://github.com/baka9moe/CVE-2021-3156-Exp
nomisec SCANNER 3 stars
by ph4ntonn · local
https://github.com/ph4ntonn/CVE-2021-3156
nomisec WORKING POC 3 stars
by elbee-cyber · poc
https://github.com/elbee-cyber/CVE-2021-3156-PATCHER
nomisec WORKING POC 3 stars
by kal1gh0st · local
https://github.com/kal1gh0st/CVE-2021-3156
nomisec WRITEUP 2 stars
by ypl6 · poc
https://github.com/ypl6/heaplens
nomisec WORKING POC 2 stars
by Q4n · local
https://github.com/Q4n/CVE-2021-3156
nomisec WORKING POC 2 stars
by musergi · local
https://github.com/musergi/CVE-2021-3156
nomisec STUB 1 stars
by BearCat4 · poc
https://github.com/BearCat4/CVE-2021-3156
nomisec SUSPICIOUS 1 stars
by binw2018 · poc
https://github.com/binw2018/CVE-2021-3156-SCRIPT
nomisec SCANNER 1 stars
by nobodyatall648 · poc
https://github.com/nobodyatall648/CVE-2021-3156
nomisec WORKING POC 1 stars
by q77190858 · local
https://github.com/q77190858/CVE-2021-3156
nomisec WORKING POC 1 stars
by DASICS-ICT · local
https://github.com/DASICS-ICT/DASICS-CVE-2021-3156
nomisec SCANNER 1 stars
by RodricBr · local
https://github.com/RodricBr/CVE-2021-3156
nomisec SCANNER 1 stars
by lypd0 · poc
https://github.com/lypd0/CVE-2021-3156-checker
nomisec WORKING POC 1 stars
by donghyunlee00 · local
https://github.com/donghyunlee00/CVE-2021-3156
nomisec WORKING POC 1 stars
by TheFlash2k · local
https://github.com/TheFlash2k/CVE-2021-3156
nomisec WORKING POC 1 stars
by unauth401 · poc
https://github.com/unauth401/CVE-2021-3156
nomisec WORKING POC 1 stars
by 0x7183 · local
https://github.com/0x7183/CVE-2021-3156
nomisec SCANNER 1 stars
by SantiagoSerrao · poc
https://github.com/SantiagoSerrao/ScannerCVE-2021-3156
nomisec WORKING POC
by hycheng15 · local
https://github.com/hycheng15/CVE-2021-3156
nomisec WRITEUP
by Shuhaib88 · local
https://github.com/Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156
nomisec WORKING POC
by Superliverbun · local
https://github.com/Superliverbun/cve-2021-3156-
nomisec WORKING POC
by mutur4 · local
https://github.com/mutur4/CVE-2021-3156
nomisec WORKING POC
by HuzaifaTariqAfzalKhan · local
https://github.com/HuzaifaTariqAfzalKhan/CVE-Exploit-Research-Development-ITSOLERA
nomisec SCANNER
by gmldbd94 · poc
https://github.com/gmldbd94/cve-2021-3156
nomisec STUB
by DanielAzulayy · poc
https://github.com/DanielAzulayy/CTF-2021
nomisec WRITEUP
by ymrsmns · poc
https://github.com/ymrsmns/CVE-2021-3156
nomisec WORKING POC
by asepsaepdin · local
https://github.com/asepsaepdin/CVE-2021-3156
nomisec WORKING POC
by wurwur · local
https://github.com/wurwur/CVE-2021-3156
nomisec WORKING POC
by Bad3r · local
https://github.com/Bad3r/CVE-2021-3156-without-ip-command
nomisec WORKING POC
by Sebastianbedoya25 · local
https://github.com/Sebastianbedoya25/CVE-2021-3156
nomisec WORKING POC
by ten-ops · local
https://github.com/ten-ops/baron-samedit
nomisec WORKING POC
by Sornphut · local
https://github.com/Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-
nomisec WORKING POC
by czeti · poc
https://github.com/czeti/baron-samedit
nomisec WORKING POC
by arvindshima · local
https://github.com/arvindshima/CVE-2021-3156
nomisec SCANNER
by VilmarTuminskii · poc
https://github.com/VilmarTuminskii/cve-2021-3156-sudo-lab
nomisec WORKING POC
by sharkmoos · local
https://github.com/sharkmoos/Baron-Samedit
nomisec WORKING POC
by CyberCommands · local
https://github.com/CyberCommands/CVE-2021-3156
nomisec WORKING POC
by capturingcats · local
https://github.com/capturingcats/CVE-2021-3156
nomisec WORKING POC
by freeFV · poc
https://github.com/freeFV/CVE-2021-3156
nomisec WORKING POC
by oneoy · local
https://github.com/oneoy/CVE-2021-3156
nomisec NO CODE
by d3c3ptic0n · poc
https://github.com/d3c3ptic0n/CVE-2021-3156
gitlab WORKING POC
by kal1gh0st · local
https://gitlab.com/kal1gh0st/CVE-2021-3156
nomisec WORKING POC
by Exodusro · poc
https://github.com/Exodusro/CVE-2021-3156
nomisec WORKING POC
by halissha · poc
https://github.com/halissha/CVE-2021-3156
gitlab SCANNER
by olegfiksel · poc
https://gitlab.com/olegfiksel/ansible_check_cve-2021-3156_sudo_vulnerability
gitlab WORKING POC
by LongChampion · poc
https://gitlab.com/LongChampion/CVE-2021-3156
nomisec WORKING POC
by TopskiyPavelQwertyGang · poc
https://github.com/TopskiyPavelQwertyGang/Review.CVE-2021-3156
nomisec WRITEUP
by perlun · poc
https://github.com/perlun/sudo-1.8.3p1-patched
nomisec STUB
by ret2basic · poc
https://github.com/ret2basic/SudoScience
nomisec STUB
by ajtech-hue · poc
https://github.com/ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build
nomisec WRITEUP
by Ashish-dawani · poc
https://github.com/Ashish-dawani/CVE-2021-3156-Patch
nomisec WORKING POC
by DDayLuong · local
https://github.com/DDayLuong/CVE-2021-3156
nomisec WORKING POC
by shishirpandey18 · local
https://github.com/shishirpandey18/CVE-2021-3156
nomisec NO CODE
by nexcess · poc
https://github.com/nexcess/sudo_cve-2021-3156
exploitdb WORKING POC
by nu11secur1ty · clocalmultiple
https://www.exploit-db.com/exploits/49522
exploitdb WORKING POC
by West Shepherd · pythonlocalmultiple
https://www.exploit-db.com/exploits/49521
vulncheck_xdb WORKING POC
local
https://github.com/Jauler/cve2021-3156-sudo-heap-overflow
vulncheck_xdb WORKING POC
local
https://github.com/barebackbandit/CVE-2021-3156
vulncheck_xdb WORKING POC
local
https://github.com/puckiestyle/CVE-2021-3156
metasploit WORKING POC EXCELLENT
by Qualys, Spencer McIntyre, bwatters-r7, smashery, blasty <[email protected]>, worawit, Alexander Krog · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/sudo_baron_samedit.rb

Nuclei Templates (1)

Sudo Baron Samedit - Local Privilege Escalation
HIGHVERIFIEDby pussycat0x

References (35)

... and 15 more

Scores

CVSS v3 7.8
EPSS 0.9231
EPSS Percentile 99.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-04-06
VulnCheck KEV 2022-04-06
InTheWild.io 2022-04-06
ENISA EUVD EUVD-2021-26500

Classification

CWE
CWE-193
Status published

Affected Products (30)

sudo_project/sudo < 1.8.32
sudo_project/sudo
sudo_project/sudo
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
netapp/active_iq_unified_manager
netapp/cloud_backup
netapp/hci_management_node
netapp/oncommand_unified_manager_core_package
netapp/ontap_select_deploy_administration_utility
netapp/ontap_tools
netapp/solidfire
mcafee/web_gateway
... and 15 more

Timeline

Published Jan 26, 2021
KEV Added Apr 06, 2022
Tracked Since Feb 18, 2026