Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
cve CVE-2025-32463 4 sources, 4 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability could affect an open-source component, third-party library, protocol, or prop… the claim
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability could affect an open-source component, third-party library, protocol, or prop… the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Stratascalereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Stratascale",
"codes": "CVE-2025-32463",
"date_added": "2025-07-08",
"date_published": "2025-07-08",
"date_updated": "2025-07-08",
"description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
"file": "exploits/linux/local/52352.txt",
"id": "52352",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Cvss cvss | Red Hat | 7.8receipt
What the source handed over{
"CVE": "CVE-2025-32463",
"CWE": "CWE-427",
"advisories": [
"RHSA-2025:11537"
],
"affected_packages": [
"sudo-0:1.9.15-8.p5.el10_0.2"
],
"bugzilla": "2374693",
"bugzilla_description": "sudo: LPE via chroot option",
"cvss3_score": "7.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-06-30T14:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
"severity": "important"
} | — |
| Cwe cwe | Red Hat | CWE-427receipt
What the source handed over{
"CVE": "CVE-2025-32463",
"CWE": "CWE-427",
"advisories": [
"RHSA-2025:11537"
],
"affected_packages": [
"sudo-0:1.9.15-8.p5.el10_0.2"
],
"bugzilla": "2374693",
"bugzilla_description": "sudo: LPE via chroot option",
"cvss3_score": "7.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-06-30T14:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
"severity": "important"
} | — |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-829receipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2025-10-20receipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Packages packages | Red Hat | sudo-0:1.9.15-8.p5.el10_0.2receipt
What the source handed over{
"CVE": "CVE-2025-32463",
"CWE": "CWE-427",
"advisories": [
"RHSA-2025:11537"
],
"affected_packages": [
"sudo-0:1.9.15-8.p5.el10_0.2"
],
"bugzilla": "2374693",
"bugzilla_description": "sudo: LPE via chroot option",
"cvss3_score": "7.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-06-30T14:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
"severity": "important"
} | — |
| Platform platform not compared | Exploit-DB | linuxreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Stratascale",
"codes": "CVE-2025-32463",
"date_added": "2025-07-08",
"date_published": "2025-07-08",
"date_updated": "2025-07-08",
"description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
"file": "exploits/linux/local/52352.txt",
"id": "52352",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Platform platform not compared | Metasploit exploit modules | Linuxreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "cmd",
"author": [
"msutovsky-r7",
"Stratascale",
"Rich Mirch"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "Sudo before version 1.19.17p1 allows user to use `chroot` option, when\n executing command. The option is intended to run a command with\n user-selected root directory (if sudoers file allow it). Change in version\n 1.9.14 allows resolving paths via `chroot` using user-specified root\n directory when sudoers is still evaluating.\n This allows the attacker to trick Sudo into loading arbitrary shared object,\n thus resulting in a privilege escalation.",
"disclosure_date": "2025-06-30",
"fullname": "exploit/linux/local/sudo_chroot_cve_2025_32463",
"is_install_path": true,
"mod_time": "2026-04-22 11:57:34 +0000",
"name": "Sudo Chroot 1.9.17 Privilege Escalation",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/sudo_chroot_cve_2025_32463.rb",
"platform": "Linux",
"post_auth": false,
"rank": 300,
"ref_name": "linux/local/sudo_chroot_cve_2025_32463",
"references": [
"EDB-52352",
"URL-https://www.helpnetsecurity.com/2025/07/01/sudo-local-privilege-escalation-vulnerabilities-fixed-cve-2025-32462-cve-2025-32463/",
"CVE-2025-32463"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Auto"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Sudoreceipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 300 Normal. Reliable against a version range the module detects. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "cmd",
"author": [
"msutovsky-r7",
"Stratascale",
"Rich Mirch"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "Sudo before version 1.19.17p1 allows user to use `chroot` option, when\n executing command. The option is intended to run a command with\n user-selected root directory (if sudoers file allow it). Change in version\n 1.9.14 allows resolving paths via `chroot` using user-specified root\n directory when sudoers is still evaluating.\n This allows the attacker to trick Sudo into loading arbitrary shared object,\n thus resulting in a privilege escalation.",
"disclosure_date": "2025-06-30",
"fullname": "exploit/linux/local/sudo_chroot_cve_2025_32463",
"is_install_path": true,
"mod_time": "2026-04-22 11:57:34 +0000",
"name": "Sudo Chroot 1.9.17 Privilege Escalation",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/sudo_chroot_cve_2025_32463.rb",
"platform": "Linux",
"post_auth": false,
"rank": 300,
"ref_name": "linux/local/sudo_chroot_cve_2025_32463",
"references": [
"EDB-52352",
"URL-https://www.helpnetsecurity.com/2025/07/01/sudo-local-privilege-escalation-vulnerabilities-fixed-cve-2025-32462-cve-2025-32463/",
"CVE-2025-32463"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Auto"
],
"type": "exploit"
} | — |
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2025-32463",
"CWE": "CWE-427",
"advisories": [
"RHSA-2025:11537"
],
"affected_packages": [
"sudo-0:1.9.15-8.p5.el10_0.2"
],
"bugzilla": "2374693",
"bugzilla_description": "sudo: LPE via chroot option",
"cvss3_score": "7.8",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-06-30T14:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-32463.json",
"severity": "important"
} | high |
| Type type | Exploit-DB | localreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Stratascale",
"codes": "CVE-2025-32463",
"date_added": "2025-07-08",
"date_published": "2025-07-08",
"date_updated": "2025-07-08",
"description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
"file": "exploits/linux/local/52352.txt",
"id": "52352",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Sudoreceipt
What the source handed over{
"cveID": "CVE-2025-32463",
"cwes": "CWE-829",
"dateAdded": "2025-09-29",
"dueDate": "2025-10-20",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.sudo.ws/security/advisories/chroot_bug/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-32463",
"product": "Sudo",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
"vendorProject": "Sudo",
"vulnerabilityName": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Stratascale",
"codes": "CVE-2025-32463",
"date_added": "2025-07-08",
"date_published": "2025-07-08",
"date_updated": "2025-07-08",
"description": "Sudo chroot 1.9.17 - Local Privilege Escalation",
"file": "exploits/linux/local/52352.txt",
"id": "52352",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "local",
"verified": "0"
} | — |
vulnerability
| Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability zetlyn/cve-kev · 2025-09-29 | cwes CWE-829 due_date 2025-10-20 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Sudo vendor_project Sudo | |
| sudo: LPE via chroot option zetlyn/cve-redhat · 2025-06-30 | cvss 7.8 cwe CWE-427 packages sudo-0:1.9.15-8.p5.el10_0.2 severity important | source |
exploit
| Sudo Chroot 1.9.17 Privilege Escalation zetlyn/cve-metasploit · 2025-06-30 | platform Linux rank 300 | source |
| Sudo chroot 1.9.17 - Local Privilege Escalation zetlyn/cve-exploitdb · 2025-07-08 | author Stratascale platform linux type local verified false | source |