Recent Linux sudo vulnerability affects a major percent of cloud workloads
ID: 9f2b49c9-75cd-559e-9bae-6b5cffcdbcac
STIX ID: report--9f2b49c9-75cd-559e-9bae-6b5cffcdbcac
Feed Name: Wiz Blog
CVE-2021-3156 is a high-severity local privilege escalation vulnerability in the ubiquitous sudo utility that allows an unprivileged local user to escalate to root without authentication. The report lists affected sudo versions (1.8.2–1.8.31p2 and 1.9.0–1.9.5p1), describes the underlying escape/unescape parsing bug triggered by sudoedit when shell mode is set, provides a simple local test (run “sudoedit -s/”), highlights broad impact across Linux cloud workloads, and recommends rapid scanning and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
