Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Loading...
Loading...
Score elevated to 9.3 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2025-09-29), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.3 retained for reference. Confidence: HIGH.
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
June 30, 2025
November 5, 2025
Affected: Ubuntu 24.04 LTS, Ubuntu 24.10, and
https://ubuntu.com/security/notices/USN-7604-1| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | sudo-ldap (1.9.15p5-3ubuntu5.24.04.1) @ noble | 2026-06-03 | ubuntu |
| redhat | sudo-0:1.9.15-8.p5.el10_0.2 | 2025-07-22 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
Open source ↗A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.
Open source ↗Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
Open source ↗Sudo chroot 1.9.17 - Local Privilege Escalation
Open source ↗A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
Open source ↗# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
Open source ↗PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability
Open source ↗Local Privilege Escalation to Root via Sudo chroot in Linux
Open source ↗CVE-2025-32463 Proof of concept
Open source ↗End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-32463
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.