peter bassill · operator
$ cve CVE-2019-14287 JSON

CVE-2019-14287 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 63.8% (pctl 99)

Patch early

A public exploit exists.

Description

In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS63.76% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-755
On CISA KEVno
Public exploityes
Published2019-10-17
Last modified2026-06-17

Affected (15)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
netappelement software management node
opensuseleap
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatopenshift container platform
redhatvirtualization
sudo projectsudo

Public exploits

SourceTitleDate
exploit-dbsudo 1.8.27 - Security Bypass2019-10-15

References

→ the Explorer  ·  watch your stack  ·  NVD