CVE-2021-3156HIGH· 7.8MITRENVDExploit-DB대응게시일: 1970. 01. 01.수정일: 2025. 11. 10.CNA: cve@mitre.orgAnalyzed
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
위협 신호 · CVSS · EPSS · KEV
즉시 패치· 실측 악용 확인 · KEV 등재
CVSS
7.8high
이론적 심각도 점수
EPSS
100.0%상위 0.0%
30일 내 악용 확률 예측
KEV
등재됨등재일 2022. 04. 06.
패치 기한 2022. 04. 27.
권장 대응 기한3일 이내+ 침해 포렌식CISA SSVC 기준
즉시 패치 + 침해 여부 포렌식 분석
KEV 악용자동화 가능완전 장악· KEV 등재 · 자동화 가능 · 완전 장악 · 내부 한정
CVSS 벡터 · 메트릭
악용 경로
공격 벡터로컬
공격 복잡도낮음
필요 권한낮음
사용자 상호작용불필요
범위불변
영향
기밀성 영향높음
무결성 영향높음
가용성 영향높음
버전별 점수
CVSS 3.17.8HIGH· 악용성 1.8· 영향도 5.9
CVSS 3.17.8HIGH· 악용성 1.8· 영향도 5.9
CVSS 2.07.2HIGH· 악용성 3.9· 영향도 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H약점 (CWE)
상세 설명
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- oracle micros_workstation_5aother
- sudo_project sudo1.8.2 - 1.8.32other
- sudo_project sudo1.9.0 - 1.9.5other
- sudo_project sudoother
- sudo_project sudoother
- fedoraproject fedoraother
- fedoraproject fedoraother
- debian debian_linuxlinux
- debian debian_linuxlinux
- netapp active_iq_unified_managerother
- netapp cloud_backupother
- netapp hci_management_nodeother
- netapp oncommand_unified_manager_core_packageother
- netapp ontap_select_deploy_administration_utilityother
- netapp ontap_toolsother
- netapp solidfireother
- mcafee web_gatewayother
- mcafee web_gatewayother
- mcafee web_gatewayother
- synology diskstation_manager_unified_controllerother
- synology diskstation_managerother
- synology skynas_firmwareother
- synology skynasother
- synology vs960hd_firmwareother
- synology vs960hdother
- beyondtrust privilege_management_for_mac< 21.1.1other
- beyondtrust privilege_management_for_unix\/linux< 10.3.2-10linux
- oracle micros_compact_workstation_3_firmwareother
- oracle micros_compact_workstation_3other
- oracle micros_es400_firmware400 - 410other
- oracle micros_es400other
- oracle micros_kitchen_display_system_firmwareother
- oracle micros_kitchen_display_systemother
- oracle micros_workstation_5a_firmwareother
- oracle micros_workstation_6_firmware610 - 655other
- oracle micros_workstation_6other
- oracle communications_performance_intelligence_center10.3.0.0.0 - 10.3.0.2.1other
- oracle communications_performance_intelligence_center10.4.0.1.0 - 10.4.0.3.1other
- oracle tekelec_platform_distribution7.4.0 - 7.7.1other
영향받는 구성 (CPE) 37
- sudo_project sudo≥ 1.8.2 < 1.8.32cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
- sudo_project sudo 1.9.5cpe:2.3:a:sudo_project:sudo:1.9.5:-:*:*:*:*:*:*
- sudo_project sudo 1.9.5cpe:2.3:a:sudo_project:sudo:1.9.5:patch1:*:*:*:*:*:*
- fedoraproject fedora 32cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- fedoraproject fedora 33cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- debian debian_linux 9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- debian debian_linux 10.0cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- netapp active_iq_unified_managercpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- netapp cloud_backupcpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- netapp hci_management_nodecpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
- netapp oncommand_unified_manager_core_packagecpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*
- netapp ontap_select_deploy_administration_utilitycpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
- netapp ontap_tools 9cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:*
- netapp solidfirecpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*
- mcafee web_gateway 8.2.17cpe:2.3:a:mcafee:web_gateway:8.2.17:*:*:*:*:*:*:*
- mcafee web_gateway 9.2.8cpe:2.3:a:mcafee:web_gateway:9.2.8:*:*:*:*:*:*:*
- mcafee web_gateway 10.0.4cpe:2.3:a:mcafee:web_gateway:10.0.4:*:*:*:*:*:*:*
- synology diskstation_manager_unified_controller 3.0cpe:2.3:a:synology:diskstation_manager_unified_controller:3.0:*:*:*:*:*:*:*
- synology diskstation_manager 6.2cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
- synology skynas_firmwarecpe:2.3:o:synology:skynas_firmware:-:*:*:*:*:*:*:*
- synology skynascpe:2.3:h:synology:skynas:-:*:*:*:*:*:*:*
- synology vs960hd_firmwarecpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*
- synology vs960hdcpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*
- beyondtrust privilege_management_for_mac< 21.1.1cpe:2.3:a:beyondtrust:privilege_management_for_mac:*:*:*:*:*:*:*:*
- beyondtrust privilege_management_for_unix/linux< 10.3.2-10cpe:2.3:a:beyondtrust:privilege_management_for_unix\/linux:*:*:*:*:basic:*:*:*
- oracle micros_compact_workstation_3_firmware 310cpe:2.3:o:oracle:micros_compact_workstation_3_firmware:310:*:*:*:*:*:*:*
- oracle micros_compact_workstation_3cpe:2.3:h:oracle:micros_compact_workstation_3:-:*:*:*:*:*:*:*
- oracle micros_es400_firmware≥ 400 ≤ 410cpe:2.3:o:oracle:micros_es400_firmware:*:*:*:*:*:*:*:*
- oracle micros_es400cpe:2.3:h:oracle:micros_es400:-:*:*:*:*:*:*:*
- oracle micros_kitchen_display_system_firmware 210cpe:2.3:o:oracle:micros_kitchen_display_system_firmware:210:*:*:*:*:*:*:*
- oracle micros_kitchen_display_systemcpe:2.3:h:oracle:micros_kitchen_display_system:-:*:*:*:*:*:*:*
- oracle micros_workstation_5a_firmware 5acpe:2.3:o:oracle:micros_workstation_5a_firmware:5a:*:*:*:*:*:*:*
- oracle micros_workstation_5acpe:2.3:h:oracle:micros_workstation_5a:-:*:*:*:*:*:*:*
- oracle micros_workstation_6_firmware≥ 610 ≤ 655cpe:2.3:o:oracle:micros_workstation_6_firmware:*:*:*:*:*:*:*:*
- oracle micros_workstation_6cpe:2.3:h:oracle:micros_workstation_6:-:*:*:*:*:*:*:*
- oracle communications_performance_intelligence_center≥ 10.3.0.0.0 ≤ 10.3.0.2.1cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*
- oracle tekelec_platform_distribution≥ 7.4.0 ≤ 7.7.1cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*
참고 자료 35
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.htmlExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.htmlExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.htmlExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.htmlExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.htmlExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Feb/42Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jan/79ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Feb/3ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/26/3ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/27/1Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/27/2Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/02/15/1ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/14/2Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/01/30/6ExploitMailing List
- https://kc.mcafee.com/corporate/index?page=content&id=SB10348Broken LinkThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00022.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202101-33Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210128-0001/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210128-0002/Third Party Advisory
- https://support.apple.com/kb/HT212177Third Party Advisory
- https://www.debian.org/security/2021/dsa-4839Third Party Advisory
- https://www.kb.cert.org/vuls/id/794544Third Party AdvisoryUS Government Resource
- https://www.openwall.com/lists/oss-security/2021/01/26/3ExploitMailing ListThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
- https://www.sudo.ws/stable.html#1.9.5p2Release Notes
- https://www.synology.com/security/advisory/Synology_SA_21_02Third Party Advisory
- https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3156US Government Resource
링크 내용 불러오는 중…