peter bassill · operator
$ cve CVE-2025-32463 JSON

CVE-2025-32463 KEV EXPLOIT

9.3
CRITICAL · CVSS 3.1 · EPSS 61% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-10-20.

Description

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Scoring

CVSS9.3 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS61.04% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-829
On CISA KEVyes — remediate by 2025-10-20
Public exploityes
Published2025-06-30
Last modified2026-06-17

CISA KEV

NameSudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Added2025-09-29
Due2025-10-20
Vendor / productSudo / Sudo
Ransomware usenone reported

Affected (8)

VendorProduct
canonicalubuntu linux
debiandebian linux
opensuseleap
redhatenterprise linux
sudo projectsudo
suselinux enterprise desktop
suselinux enterprise real time
suselinux enterprise server for sap

Public exploits

SourceTitleDate
exploit-dbSudo chroot 1.9.17 - Local Privilege Escalation2025-07-08

References

→ the Explorer  ·  watch your stack  ·  NVD