CVE-2019-14287
HIGH NUCLEISudo <1.8.28 - Privilege Escalation
Title source: llmDescription
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Exploits (29)
exploitdb
WORKING POC
by Mohin Paramasivam · pythonlocallinux
https://www.exploit-db.com/exploits/47502
nomisec
WORKING POC
3 stars
by shallvhack · poc
https://github.com/shallvhack/Sudo-Security-Bypass-CVE-2019-14287
nomisec
WORKING POC
1 stars
by CashWilliams · poc
https://github.com/CashWilliams/CVE-2019-14287-demo
nomisec
WORKING POC
by HivinManjuSri · poc
https://github.com/HivinManjuSri/ubuntu-cve-2019-14287-patch-manager
github
WRITEUP
by Zahid-secure · poc
https://github.com/Zahid-secure/cve-walkthrough-labs/tree/main/2019/CVE-2019-14287-AgentSudo-tryhackme
nomisec
SUSPICIOUS
by Hasintha-98 · poc
https://github.com/Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
nomisec
STUB
by DularaAnushka · poc
https://github.com/DularaAnushka/Linux-Privilege-Escalation-using-Sudo-Rights
nomisec
NO CODE
by janod313 · poc
https://github.com/janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
nomisec
NO CODE
by thinuri99 · poc
https://github.com/thinuri99/Sudo-Security-Bypass-Vulnerability-CVE-2019-14287-
nomisec
NO CODE
by ShianTrish · poc
https://github.com/ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-14287
nomisec
NO CODE
by sachinthadesilva · poc
https://github.com/sachinthadesilva/Exploit-CVE-2019-14287
Nuclei Templates (1)
Sudo <= 1.8.27 - Security Bypass
HIGHVERIFIEDby daffainfo
References (37)
Scores
CVSS v3
8.8
EPSS
0.8581
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-755
Status
published
Products (47)
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
19.04
debian/debian_linux
8.0
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
29
fedoraproject/fedora
30
... and 37 more
Published
Oct 17, 2019
Tracked Since
Feb 18, 2026