This document describes a threat finding type in Security Command Center. Threat findings are generated by threat detectors when they detect a potential threat in your cloud resources. For a full list of available threat findings, see Threat findings index.
Overview
sudo or sudoedit has been executed by an unprivileged user with command-line
arguments -s or -i and an argument that ends with a ``. This is an attempt
to exploit the CVE-2021-3156 vulnerability to elevate the user's privileges to
root level access.
How to respond
To respond to this finding, do the following:
Review finding details
Open the
Privilege Escalation: Sudo Potential Privilege Escalation (CVE-2021-3156)finding as directed in Reviewing findings. Review the details on the Summary and JSON tabs.On the Summary tab, review the information in the following sections.
- What was detected, especially the following fields:
- Program binary: the absolute path of the executed binary
- Arguments: the arguments passed during binary execution
- Affected resource, especially the following fields:
- Resource full name: the full resource name of the affected Cloud Run resource
- What was detected, especially the following fields:
On the JSON tab, note the following fields.
resource:project_display_name: the name of the project that contains the affected Cloud Run resource
finding:processes:binary:path: the full path of the executed binary
args: the arguments that were provided when the binary was executed
Identify other findings that occurred at a similar time for the affected container. Related findings might indicate that this activity was malicious, instead of a failure to follow best practices.
Review the settings of the affected container.
Check the logs for the affected container.
Research attack and response methods
- Review MITRE ATT&CK framework entries for this finding type: Privilege Escalation.
- To develop a response plan, combine your investigation results with MITRE research.
Implement your response
For response recommendations, see Respond to Cloud Run threat findings.
What's next
- Learn how to work with threat findings in Security Command Center.
- Refer to the Threat findings index.
- Learn how to review a finding through the Google Cloud console.
- Learn about the services that generate threat findings.