Feb 5, 2021

PoC for CVE-2021-3156 (sudoedit)

This is a heap-based buffer overflow for sudo/sudoedit. The full advisory can be found at https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt

Here's the local PoC for the vulnerability. The exploit is very straight forward, and done within seconds.

CVE-2021-3156 PoC 

There is another PoC that can be found at https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2021-3156

KennaSecurity has rated this CVE with risk score of 33/100. 

Kenna Risk Score