CVE-2019-14287

HIGH NUCLEI

Sudo <1.8.28 - Privilege Escalation

Title source: llm

Description

In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.

Exploits (28)

nomisec WORKING POC 12 stars
by n0w4n · poc
https://github.com/n0w4n/CVE-2019-14287
nomisec WORKING POC 7 stars
by CMNatic · poc
https://github.com/CMNatic/Dockerized-CVE-2019-14287
nomisec WORKING POC 3 stars
by shallvhack · poc
https://github.com/shallvhack/Sudo-Security-Bypass-CVE-2019-14287
nomisec WORKING POC 1 stars
by CashWilliams · poc
https://github.com/CashWilliams/CVE-2019-14287-demo
nomisec WORKING POC 1 stars
by MariliaMeira · poc
https://github.com/MariliaMeira/CVE-2019-14287
nomisec WRITEUP 1 stars
by FauxFaux · poc
https://github.com/FauxFaux/sudo-cve-2019-14287
nomisec NO CODE
by Sindayifu · poc
https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271
nomisec WORKING POC
by edsonjt81 · poc
https://github.com/edsonjt81/CVE-2019-14287-
nomisec WRITEUP
by gurneesh · poc
https://github.com/gurneesh/CVE-2019-14287-write-up
nomisec NO CODE
by sachinthadesilva · poc
https://github.com/sachinthadesilva/Exploit-CVE-2019-14287
nomisec NO CODE
by janod313 · poc
https://github.com/janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
nomisec NO CODE
by ejlevin99 · poc
https://github.com/ejlevin99/Sudo-Security-Bypass-Vulnerability
nomisec WORKING POC
by axax002 · poc
https://github.com/axax002/sudo-vulnerability-CVE-2019-14287
nomisec WORKING POC
by lemonadern · poc
https://github.com/lemonadern/poc-cve-2019-14287
nomisec NO CODE
by ShianTrish · poc
https://github.com/ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-14287
nomisec STUB
by DularaAnushka · poc
https://github.com/DularaAnushka/Linux-Privilege-Escalation-using-Sudo-Rights
nomisec WORKING POC
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2019-14287
nomisec NO CODE
by thinuri99 · poc
https://github.com/thinuri99/Sudo-Security-Bypass-Vulnerability-CVE-2019-14287-
nomisec STUB
by HussyCool · poc
https://github.com/HussyCool/CVE-2019-14287-IT18030372-
nomisec WORKING POC
by M108Falcon · poc
https://github.com/M108Falcon/Sudo-CVE-2019-14287
github WRITEUP
by Zahid-secure · poc
https://github.com/Zahid-secure/cve-walkthrough-labs/tree/main/2019/CVE-2019-14287-AgentSudo-tryhackme
nomisec SUSPICIOUS
by Hasintha-98 · poc
https://github.com/Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
nomisec NO CODE
by Sindadziy · poc
https://github.com/Sindadziy/cve-2019-14287
nomisec NO CODE
by DewmiApsara · poc
https://github.com/DewmiApsara/CVE-2019-14287
nomisec WRITEUP
by huang919 · poc
https://github.com/huang919/cve-2019-14287-PPT
nomisec NO CODE
by wenyu1999 · poc
https://github.com/wenyu1999/sudo-
exploitdb WORKING POC
by Mohin Paramasivam · pythonlocallinux
https://www.exploit-db.com/exploits/47502

Nuclei Templates (1)

Sudo <= 1.8.27 - Security Bypass
HIGHVERIFIEDby daffainfo

References (37)

... and 17 more

Scores

CVSS v3 8.8
EPSS 0.8581
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-755
Status published

Affected Products (47)

sudo_project/sudo < 1.8.28
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
debian/debian_linux
opensuse/leap
opensuse/leap
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
netapp/element_software_management_node
... and 32 more

Timeline

Published Oct 17, 2019
Tracked Since Feb 18, 2026