CVE-2019-14287
HIGH NUCLEISudo <1.8.28 - Privilege Escalation
Title source: llmDescription
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Exploits (28)
nomisec
WORKING POC
3 stars
by shallvhack · poc
https://github.com/shallvhack/Sudo-Security-Bypass-CVE-2019-14287
nomisec
WORKING POC
1 stars
by CashWilliams · poc
https://github.com/CashWilliams/CVE-2019-14287-demo
nomisec
NO CODE
by sachinthadesilva · poc
https://github.com/sachinthadesilva/Exploit-CVE-2019-14287
nomisec
NO CODE
by janod313 · poc
https://github.com/janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
nomisec
NO CODE
by ShianTrish · poc
https://github.com/ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-14287
nomisec
STUB
by DularaAnushka · poc
https://github.com/DularaAnushka/Linux-Privilege-Escalation-using-Sudo-Rights
nomisec
NO CODE
by thinuri99 · poc
https://github.com/thinuri99/Sudo-Security-Bypass-Vulnerability-CVE-2019-14287-
github
WRITEUP
by Zahid-secure · poc
https://github.com/Zahid-secure/cve-walkthrough-labs/tree/main/2019/CVE-2019-14287-AgentSudo-tryhackme
nomisec
SUSPICIOUS
by Hasintha-98 · poc
https://github.com/Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
exploitdb
WORKING POC
by Mohin Paramasivam · pythonlocallinux
https://www.exploit-db.com/exploits/47502
Nuclei Templates (1)
Sudo <= 1.8.27 - Security Bypass
HIGHVERIFIEDby daffainfo
References (37)
... and 17 more
Scores
CVSS v3
8.8
EPSS
0.8581
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-755
Status
published
Affected Products (47)
sudo_project/sudo
< 1.8.28
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
debian/debian_linux
opensuse/leap
opensuse/leap
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
netapp/element_software_management_node
... and 32 more
Timeline
Published
Oct 17, 2019
Tracked Since
Feb 18, 2026