Zetlyn

Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

cve CVE-2025-32463 4 sources, 4 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability could affect an open-source component, third-party library, protocol, or prop… the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBStratascale
receipt
Source
Exploit-DB
Its words
Stratascale
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Stratascale",
  "codes": "CVE-2025-32463",
  "date_added": "2025-07-08",
  "date_published": "2025-07-08",
  "date_updated": "2025-07-08",
  "description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
  "file": "exploits/linux/local/52352.txt",
  "id": "52352",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Cvss
cvss
Red Hat7.8
receipt
Source
Red Hat
Its words
7.8
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-32463",
  "CWE": "CWE-427",
  "advisories": [
    "RHSA-2025:11537"
  ],
  "affected_packages": [
    "sudo-0:1.9.15-8.p5.el10_0.2"
  ],
  "bugzilla": "2374693",
  "bugzilla_description": "sudo: LPE via chroot option",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-06-30T14:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
  "severity": "important"
}
—
Cwe
cwe
Red HatCWE-427
receipt
Source
Red Hat
Its words
CWE-427
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-32463",
  "CWE": "CWE-427",
  "advisories": [
    "RHSA-2025:11537"
  ],
  "affected_packages": [
    "sudo-0:1.9.15-8.p5.el10_0.2"
  ],
  "bugzilla": "2374693",
  "bugzilla_description": "sudo: LPE via chroot option",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-06-30T14:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
  "severity": "important"
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-829
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-829
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-10-20
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-10-20
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Packages
packages
Red Hatsudo-0:1.9.15-8.p5.el10_0.2
receipt
Source
Red Hat
Its words
sudo-0:1.9.15-8.p5.el10_0.2
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-32463",
  "CWE": "CWE-427",
  "advisories": [
    "RHSA-2025:11537"
  ],
  "affected_packages": [
    "sudo-0:1.9.15-8.p5.el10_0.2"
  ],
  "bugzilla": "2374693",
  "bugzilla_description": "sudo: LPE via chroot option",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-06-30T14:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
  "severity": "important"
}
—
Platform
platform
not compared
Exploit-DBlinux
receipt
Source
Exploit-DB
Its words
linux
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Stratascale",
  "codes": "CVE-2025-32463",
  "date_added": "2025-07-08",
  "date_published": "2025-07-08",
  "date_updated": "2025-07-08",
  "description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
  "file": "exploits/linux/local/52352.txt",
  "id": "52352",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 12:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "cmd",
  "author": [
    "msutovsky-r7",
    "Stratascale",
    "Rich Mirch"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "Sudo before version 1.19.17p1 allows user to use `chroot` option, when\n          executing command. The option is intended to run a command with\n          user-selected root directory (if sudoers file allow it). Change in version\n          1.9.14 allows resolving paths via `chroot` using user-specified root\n          directory when sudoers is still evaluating.\n          This allows the attacker to trick Sudo into loading arbitrary shared object,\n          thus resulting in a privilege escalation.",
  "disclosure_date": "2025-06-30",
  "fullname": "exploit/linux/local/sudo_chroot_cve_2025_32463",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:34 +0000",
  "name": "Sudo Chroot 1.9.17 Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/sudo_chroot_cve_2025_32463.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 300,
  "ref_name": "linux/local/sudo_chroot_cve_2025_32463",
  "references": [
    "EDB-52352",
    "URL-https://www.helpnetsecurity.com/2025/07/01/sudo-local-privilege-escalation-vulnerabilities-fixed-cve-2025-32462-cve-2025-32463/",
    "CVE-2025-32463"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesSudo
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Sudo
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Rank
rank
Metasploit exploit modules300
Normal. Reliable against a version range the module detects.
receipt
Source
Metasploit exploit modules
Its words
300
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 12:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "cmd",
  "author": [
    "msutovsky-r7",
    "Stratascale",
    "Rich Mirch"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "Sudo before version 1.19.17p1 allows user to use `chroot` option, when\n          executing command. The option is intended to run a command with\n          user-selected root directory (if sudoers file allow it). Change in version\n          1.9.14 allows resolving paths via `chroot` using user-specified root\n          directory when sudoers is still evaluating.\n          This allows the attacker to trick Sudo into loading arbitrary shared object,\n          thus resulting in a privilege escalation.",
  "disclosure_date": "2025-06-30",
  "fullname": "exploit/linux/local/sudo_chroot_cve_2025_32463",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:34 +0000",
  "name": "Sudo Chroot 1.9.17 Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/sudo_chroot_cve_2025_32463.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 300,
  "ref_name": "linux/local/sudo_chroot_cve_2025_32463",
  "references": [
    "EDB-52352",
    "URL-https://www.helpnetsecurity.com/2025/07/01/sudo-local-privilege-escalation-vulnerabilities-fixed-cve-2025-32462-cve-2025-32463/",
    "CVE-2025-32463"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
—
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-32463",
  "CWE": "CWE-427",
  "advisories": [
    "RHSA-2025:11537"
  ],
  "affected_packages": [
    "sudo-0:1.9.15-8.p5.el10_0.2"
  ],
  "bugzilla": "2374693",
  "bugzilla_description": "sudo: LPE via chroot option",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-06-30T14:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
  "severity": "important"
}
high
Type
type
Exploit-DBlocal
receipt
Source
Exploit-DB
Its words
local
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Stratascale",
  "codes": "CVE-2025-32463",
  "date_added": "2025-07-08",
  "date_published": "2025-07-08",
  "date_updated": "2025-07-08",
  "description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
  "file": "exploits/linux/local/52352.txt",
  "id": "52352",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesSudo
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Sudo
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-32463",
  "cwes": "CWE-829",
  "dateAdded": "2025-09-29",
  "dueDate": "2025-10-20",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
  "product": "Sudo",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
  "vendorProject": "Sudo",
  "vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Stratascale",
  "codes": "CVE-2025-32463",
  "date_added": "2025-07-08",
  "date_published": "2025-07-08",
  "date_updated": "2025-07-08",
  "description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
  "file": "exploits/linux/local/52352.txt",
  "id": "52352",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—

vulnerability

Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
zetlyn/cve-kev · 2025-09-29
cwes CWE-829 due_date 2025-10-20 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Sudo vendor_project Sudo
sudo: LPE via chroot option
zetlyn/cve-redhat · 2025-06-30
cvss 7.8 cwe CWE-427 packages sudo-0:1.9.15-8.p5.el10_0.2 severity important source

exploit

Sudo Chroot 1.9.17 Privilege Escalation
zetlyn/cve-metasploit · 2025-06-30
platform Linux rank 300 source
Sudo chroot 1.9.17 - Local Privilege Escalation
zetlyn/cve-exploitdb · 2025-07-08
author Stratascale platform linux type local verified false source