Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35535

Опубликовано: 03 апр. 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 7.8
EPSS Низкий

Описание

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
Версия до 1.9.17 (исключая)
cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:p1:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:p2:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:*
Версия до 4.0 (исключая)
cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00173
Низкий

7.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-271
CWE-272

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
redhat
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

CVSS3: 7.4
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.4
debian
4 месяца назад

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid ...

suse-cvrf
3 месяца назад

Security update for sudo

EPSS

Процентиль: 7%
0.00173
Низкий

7.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-271
CWE-272