CVE-2025-32463
CVE-2025-32463
En resumen
Sudo anterior a la versión 1.9.17p1 tiene una falla crítica donde lee archivos de configuración de directorios controlados por el usuario al usar la opción --chroot, permitiendo que usuarios locales engañen a sudo para ejecutar comandos como root.
Detalle técnico
Vulnerabilidad CWE-829 (Ruta de Búsqueda No Confiable) en --chroot de sudo permite escalación local de privilegios mediante /etc/nsswitch.conf malicioso en directorios controlados por el atacante. La explotación requiere acceso local y capacidad de controlar el contenido del directorio antes de la ejecución de sudo con --chroot; la explotación exitosa otorga ejecución arbitraria de comandos como root.
Resumen generado y traducido por IA a partir de la descripción oficial.
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Sudo project · SudoPoCs públicas encontradas — 62
githubgithub.com/pr0v3rbs/CVE-2025-32463_chwoot★ 527githubgithub.com/kh4sh3i/CVE-2025-32463★ 466githubgithub.com/MohamedKarrab/CVE-2025-32463★ 48githubgithub.com/K1tt3h/CVE-2025-32463-POC★ 29githubgithub.com/mirchr/CVE-2025-32463-sudo-chwoot★ 25githubgithub.com/zinzloun/CVE-2025-32463★ 15githubgithub.com/Nowafen/CVE-2025-32463★ 13githubgithub.com/AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462★ 11githubgithub.com/IC3-512/linux-root-kit★ 10githubgithub.com/K3ysTr0K3R/CVE-2025-32463-EXPLOIT★ 9githubgithub.com/Maalfer/Sudo-CVE-2021-3156★ 8githubgithub.com/FreeDurok/CVE-2025-32463-PoC★ 5githubgithub.com/SysMancer/CVE-2025-32463★ 4githubgithub.com/y4ney/CVE-2025-32463-lab★ 4githubgithub.com/Yuy0ung/CVE-2025-32463_chwoot★ 3githubgithub.com/pevinkumar10/CVE-2025-32463★ 3githubgithub.com/7r00t/cve-2025-32463-lab★ 2githubgithub.com/KaiHT-Ladiant/CVE-2025-32463★ 2githubgithub.com/Mikivirus0/sudoinjection★ 2githubgithub.com/abrewer251/CVE-2025-32463_Sudo_PoC★ 1githubgithub.com/0xb0rn3/CVE-2025-32463-EXPLOIT★ 1githubgithub.com/4f-kira/CVE-2025-32463★ 1githubgithub.com/krypton-0x00/CVE-2025-32463-Chwoot-POC★ 1githubgithub.com/ashardev002/CVE-2025-32463_chwoot★ 1githubgithub.com/0p5cur/CVE-2025-32463-POC★ 1githubgithub.com/dr4xp/sudo-chroot★ 1githubgithub.com/Chocapikk/CVE-2025-32463-lab★ 1githubgithub.com/san8383/CVE-2025-32463★ 1githubgithub.com/aexdyhaxor/CVE-2025-32463★ 1githubgithub.com/SpongeBob-369/cve-2025-32463★ 1githubgithub.com/ChetanKomal/sudo_exploit★ 0githubgithub.com/neko205-mx/CVE-2025-32463_Exploit★ 0githubgithub.com/zhaduchanhzz/CVE-2025-32463_POC★ 0githubgithub.com/robbert1978/CVE-2025-32463_POC★ 0githubgithub.com/0xAkarii/CVE-2025-32463★ 0githubgithub.com/CIA911/sudo_patch_CVE-2025-32463★ 0githubgithub.com/ill-deed/CVE-2025-32463_illdeed★ 0githubgithub.com/gmh5225/Blackash-CVE-2025-32463★ 0githubgithub.com/lowercasenumbers/CVE-2025-32463_sudo_chroot★ 0githubgithub.com/morgenm/sudo-chroot-CVE-2025-32463★ 0githubgithub.com/Floodnut/CVE-2025-32463★ 0githubgithub.com/Rajneeshkarya/CVE-2025-32463★ 0githubgithub.com/MGunturG/CVE-2025-32463★ 0githubgithub.com/daryllundy/CVE-2025-32463★ 0githubgithub.com/aldoClau98/CVE-2025-32463★ 0githubgithub.com/painoob/CVE-2025-32463★ 0githubgithub.com/hacieda/CVE-2025-32463★ 0githubgithub.com/blackcat4347/CVE-2025-32463_PoC★ 0githubgithub.com/D3ltaFormation/CVE-2025-32463-Sudo-Chroot-Escape★ 0githubgithub.com/AC8999/CVE-2025-32463★ 0githubgithub.com/Ghstxz/CVE-2025-32463★ 0githubgithub.com/ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation★ 0githubgithub.com/justjoeyking/CVE-2025-32463★ 0githubgithub.com/Mr-Alperen/CVE-2025-32463★ 0githubgithub.com/SpycioKon/CVE-2025-32463★ 0githubgithub.com/vpr-labs/CVE-2025-32463★ 0githubgithub.com/danilo1992-sys/CVE-2025-32463★ 0githubgithub.com/0xBlackash/CVE-2025-32463★ 0githubgithub.com/0xzap/CVE-2025-32463★ 0githubgithub.com/Fomovet/cve-2025-32463★ 0exploitdbwww.exploit-db.com/exploits/52352no verificadocve_referenceiototsecnews.jp/2025/07/01/linux-sudo-chroot-vulnerability-enables-hackers-to-elevate-privileges-to-root/no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/security/cve/cve-2025-32463https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32463https://explore.alas.aws.amazon.com/CVE-2025-32463.htmlhttps://iototsecnews.jp/2025/07/01/linux-sudo-chroot-vulnerability-enables-hackers-to-elevate-privileges-to-root/https://security-tracker.debian.org/tracker/CVE-2025-32463https://ubuntu.com/security/notices/USN-7604-1https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32463https://www.openwall.com/lists/oss-security/2025/06/30/3https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroothttps://www.sudo.ws/releases/changelog/https://www.sudo.ws/security/advisories/