> Source: [sk171751](https://support.checkpoint.com/results/sk/sk171751)

# sk171751 - Check Point Response to CVE-2021-3156 - sudo Privilege Escalation

| Property | Value |
|----------|-------|
| Solution ID | sk171751 |
| Date Created | 2021-01-28 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Spark Firewall (Locally Managed) |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R81.10.X, R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * [CVE-2021-3156](https://www.cve.org/CVERecord?id=CVE-2021-3156) states: "Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character."

* For more information, refer to <https://www.sudo.ws/stable.html#1.9.5p2>

## Solution

Check Point is not exploitable to this CVE because to run the `sudo` or `sudoedit` command you need to be in the Expert mode, which means that you are already an administrator, and the privilege escalation is meaningless.

Users in the Gaia OS are not configured to run the `sudo` command (not "`sudoers`").

Quantum Spark Appliances (that run the Gaia Embedded OS) are not vulnerable because they do not use `sudo` at all.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
