EXPOSURES › CVE-2025-32463
CVE-2025-32463
HIGH ⌖ ON CISA KEV · EXPLOITEDSudo's -R option enabled local users to execute arbitrary commands as root without being in sudoers file
Sudo, a common Linux utility for running commands with superuser privileges, contained a vulnerability that allowed local attackers to execute arbitrary commands as root by leveraging the -R option. This bypassed the usual restrictions in the sudoers file, posing a significant security risk to organizations using Sudo.
Shame score — Critical local privilege escalation vulnerability that was actively exploited.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.