Skip to content
COOEY

EXPOSURES › CVE-2025-32463

CVE-2025-32463

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-09-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-32463 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatchedprivilege-escalation

Sudo's -R option enabled local users to execute arbitrary commands as root without being in sudoers file

Sudo, a common Linux utility for running commands with superuser privileges, contained a vulnerability that allowed local attackers to execute arbitrary commands as root by leveraging the -R option. This bypassed the usual restrictions in the sudoers file, posing a significant security risk to organizations using Sudo.

Shame score — Critical local privilege escalation vulnerability that was actively exploited.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.