CVE-2025-32463 KEV EXPLOIT
9.3
CRITICAL · CVSS 3.1 · EPSS 61% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2025-10-20.
Description
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Scoring
| CVSS | 9.3 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 61.04% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-829 |
| On CISA KEV | yes — remediate by 2025-10-20 |
| Public exploit | yes |
| Published | 2025-06-30 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability |
|---|---|
| Added | 2025-09-29 |
| Due | 2025-10-20 |
| Vendor / product | Sudo / Sudo |
| Ransomware use | none reported |
Affected (8)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| opensuse | leap |
| redhat | enterprise linux |
| sudo project | sudo |
| suse | linux enterprise desktop |
| suse | linux enterprise real time |
| suse | linux enterprise server for sap |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sudo chroot 1.9.17 - Local Privilege Escalation | 2025-07-08 |
References
- https://access.redhat.com/security/cve/cve-2025-32463
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463
- https://explore.alas.aws.amazon.com/CVE-2025-32463.html
- https://security-tracker.debian.org/tracker/CVE-2025-32463
- https://ubuntu.com/security/notices/USN-7604-1
- https://www.openwall.com/lists/oss-security/2025/06/30/3
- https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/
- https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
- https://www.sudo.ws/releases/changelog/
- https://www.sudo.ws/security/advisories/
- https://www.sudo.ws/security/advisories/chroot_bug/
- https://www.suse.com/security/cve/CVE-2025-32463.html
- https://www.suse.com/support/update/announcement/2025/suse-su-202502177-1/
- https://www.vicarius.io/vsociety/posts/cve-2025-32463-detect-sudo-vulnerability
- https://www.vicarius.io/vsociety/posts/cve-2025-32463-mitigate-sudo-vulnerability
- https://iototsecnews.jp/2025/07/01/linux-sudo-chroot-vulnerability-enables-hackers-to-elevate-privileges-to-root/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32463
→ the Explorer · watch your stack · NVD