CVE-2025-32463

CRITICAL KEV

Sudo <1.9.17p1 - Privilege Escalation

Title source: llm

Description

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Exploits (95)

nomisec WORKING POC 514 stars
by pr0v3rbs · local
https://github.com/pr0v3rbs/CVE-2025-32463_chwoot
nomisec WORKING POC 448 stars
by kh4sh3i · local
https://github.com/kh4sh3i/CVE-2025-32463
nomisec WORKING POC 45 stars
by MohamedKarrab · local
https://github.com/MohamedKarrab/CVE-2025-32463
nomisec WORKING POC 24 stars
by K1tt3h · local
https://github.com/K1tt3h/CVE-2025-32463-POC
nomisec WORKING POC 23 stars
by mirchr · local
https://github.com/mirchr/CVE-2025-32463-sudo-chwoot
nomisec WORKING POC 13 stars
by Nowafen · poc
https://github.com/Nowafen/CVE-2025-32463
nomisec WORKING POC 13 stars
by zinzloun · local
https://github.com/zinzloun/CVE-2025-32463
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-32463
nomisec WORKING POC 9 stars
by IC3-512 · poc
https://github.com/IC3-512/linux-root-kit
nomisec WRITEUP 8 stars
by AdityaBhatt3010 · poc
https://github.com/AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462
nomisec WORKING POC 6 stars
by Maalfer · poc
https://github.com/Maalfer/Sudo-CVE-2021-3156
nomisec WORKING POC 6 stars
by K3ysTr0K3R · local
https://github.com/K3ysTr0K3R/CVE-2025-32463-EXPLOIT
nomisec WORKING POC 5 stars
by FreeDurok · local
https://github.com/FreeDurok/CVE-2025-32463-PoC
github WORKING POC 5 stars
by MAAYTHM · shelllocal
https://github.com/MAAYTHM/CVE-2025-32462_32463-Lab
github WORKING POC 4 stars
by behnamvanda · shelllocal
https://github.com/behnamvanda/CVE-2025-32463
nomisec WORKING POC 4 stars
by SysMancer · local
https://github.com/SysMancer/CVE-2025-32463
nomisec WORKING POC 4 stars
by y4ney · local
https://github.com/y4ney/CVE-2025-32463-lab
nomisec WORKING POC 3 stars
by nflatrea · local
https://github.com/nflatrea/CVE-2025-32463
nomisec WORKING POC 2 stars
by KaiHT-Ladiant · local
https://github.com/KaiHT-Ladiant/CVE-2025-32463
nomisec WORKING POC 2 stars
by pevinkumar10 · local
https://github.com/pevinkumar10/CVE-2025-32463
github SCANNER 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-32463
nomisec WORKING POC 2 stars
by Yuy0ung · local
https://github.com/Yuy0ung/CVE-2025-32463_chwoot
nomisec WORKING POC 2 stars
by Mikivirus0 · local
https://github.com/Mikivirus0/sudoinjection
nomisec WORKING POC 2 stars
by 7r00t · poc
https://github.com/7r00t/cve-2025-32463-lab
github WORKING POC 1 stars
by dr4x-c0d3r · pythonlocal
https://github.com/dr4x-c0d3r/sudo-chroot
github SUSPICIOUS 1 stars
by r3dBust3r · shellpoc
https://github.com/r3dBust3r/CVE-2025-32463
nomisec WORKING POC 1 stars
by san8383 · local
https://github.com/san8383/CVE-2025-32463
nomisec WORKING POC 1 stars
by ashardev002 · local
https://github.com/ashardev002/CVE-2025-32463_chwoot
nomisec WORKING POC 1 stars
by dr4xp · local
https://github.com/dr4xp/sudo-chroot
nomisec WORKING POC 1 stars
by krypton-0x00 · local
https://github.com/krypton-0x00/CVE-2025-32463-Chwoot-POC
nomisec WORKING POC 1 stars
by wvverez · local
https://github.com/wvverez/CVE-2025-32463
nomisec WORKING POC 1 stars
by 0p5cur · poc
https://github.com/0p5cur/CVE-2025-32463-POC
github WORKING POC 1 stars
by NewComrade12211 · shelllocal
https://github.com/NewComrade12211/CVE-2025-32463
nomisec WORKING POC 1 stars
by 4f-kira · local
https://github.com/4f-kira/CVE-2025-32463
nomisec WORKING POC 1 stars
by SpongeBob-369 · local
https://github.com/SpongeBob-369/cve-2025-32463
nomisec WORKING POC 1 stars
by abrewer251 · local
https://github.com/abrewer251/CVE-2025-32463_Sudo_PoC
github WORKING POC 1 stars
by cybershaolin47 · shellpoc
https://github.com/cybershaolin47/CVE-2025-32463_POC
nomisec WORKING POC 1 stars
by 0xb0rn3 · local
https://github.com/0xb0rn3/CVE-2025-32463-EXPLOIT
nomisec STUB 1 stars
by Chocapikk · poc
https://github.com/Chocapikk/CVE-2025-32463-lab
github WORKING POC
by shazed-x · shellpoc
https://github.com/shazed-x/CVE-2025-32463
nomisec WRITEUP
by CIA911 · poc
https://github.com/CIA911/sudo_patch_CVE-2025-32463
nomisec WORKING POC
by mihnasdsad · poc
https://github.com/mihnasdsad/CVE-2025-32463
nomisec WORKING POC
by Mr-Alperen · poc
https://github.com/Mr-Alperen/CVE-2025-32463
nomisec STUB
by Floodnut · poc
https://github.com/Floodnut/CVE-2025-32463
nomisec SCANNER
by daryllundy · poc
https://github.com/daryllundy/CVE-2025-32463
nomisec WORKING POC
by robbert1978 · poc
https://github.com/robbert1978/CVE-2025-32463_POC
nomisec WORKING POC
by SpycioKon · poc
https://github.com/SpycioKon/CVE-2025-32463
gitlab WORKING POC
by lowercasenumbers · poc
https://gitlab.com/lowercasenumbers/cve-2025-32463
gitlab WORKING POC
by FR4NC0X · poc
https://gitlab.com/FR4NC0X/sudo-chroot
nomisec WORKING POC
by neko205-mx · local
https://github.com/neko205-mx/CVE-2025-32463_Exploit
nomisec WORKING POC
by zhaduchanhzz · local
https://github.com/zhaduchanhzz/CVE-2025-32463_POC
nomisec WORKING POC
by 0xAkarii · local
https://github.com/0xAkarii/CVE-2025-32463
nomisec WORKING POC
by ill-deed · local
https://github.com/ill-deed/CVE-2025-32463_illdeed
nomisec WORKING POC
by yeremeu · local
https://github.com/yeremeu/CVE-2025-32463_chwoot
nomisec WORKING POC
by lowercasenumbers · local
https://github.com/lowercasenumbers/CVE-2025-32463_sudo_chroot
nomisec WORKING POC
by morgenm · local
https://github.com/morgenm/sudo-chroot-CVE-2025-32463
nomisec WORKING POC
by Rajneeshkarya · local
https://github.com/Rajneeshkarya/CVE-2025-32463
nomisec WORKING POC
by MGunturG · local
https://github.com/MGunturG/CVE-2025-32463
nomisec WORKING POC
by ChetanKomal · local
https://github.com/ChetanKomal/sudo_exploit
nomisec WORKING POC
by aldoClau98 · local
https://github.com/aldoClau98/CVE-2025-32463
nomisec WORKING POC
by painoob · local
https://github.com/painoob/CVE-2025-32463
nomisec WORKING POC
by blackcat4347 · local
https://github.com/blackcat4347/CVE-2025-32463_PoC
nomisec WORKING POC
by AC8999 · local
https://github.com/AC8999/CVE-2025-32463
nomisec WORKING POC
by ankitpandey383 · local
https://github.com/ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation
nomisec WORKING POC
by justjoeyking · local
https://github.com/justjoeyking/CVE-2025-32463
nomisec WORKING POC
by aexdyhaxor · local
https://github.com/aexdyhaxor/CVE-2025-32463
nomisec WORKING POC
by danilo1992-sys · local
https://github.com/danilo1992-sys/CVE-2025-32463
nomisec WORKING POC
by D3ltaFormation · poc
https://github.com/D3ltaFormation/CVE-2025-32463-Sudo-Chroot-Escape
github WORKING POC
by onniio · shelllocal
https://github.com/onniio/CVE-2025-32463
github WORKING POC
by 0x3c4dfa1 · shellpoc
https://github.com/0x3c4dfa1/CVE-2025-32463
github WORKING POC
by muhammedkayag · shellpoc
https://github.com/muhammedkayag/CVE-2025-32463
github WORKING POC
by khoazero123 · local
https://github.com/khoazero123/CVE-2025-32463
github NO CODE
by lakshan-sameera · poc
https://github.com/lakshan-sameera/CVE-2025-32462-and-CVE-2025-32463---Critical-Sudo-Vulnerabilities
nomisec WORKING POC
by zaryouhashraf · poc
https://github.com/zaryouhashraf/CVE-2025-32463
nomisec WORKING POC
by 0xAshwesker · poc
https://github.com/0xAshwesker/CVE-2025-32463
github WORKING POC
by wnaspy · shellpoc
https://github.com/wnaspy/CVE-POC-WEAPON/tree/main/CVE-2025-32463.sh
nomisec WORKING POC
by vpr-labs · poc
https://github.com/vpr-labs/CVE-2025-32463
nomisec WORKING POC
by dbarquero · poc
https://github.com/dbarquero/cve-2025-32463-lab
nomisec WORKING POC
by gmh5225 · poc
https://github.com/gmh5225/Blackash-CVE-2025-32463
metasploit WORKING POC NORMAL
by msutovsky-r7, Stratascale, Rich Mirch · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/sudo_chroot_cve_2025_32463.rb
vulncheck_xdb WORKING POC
local
https://github.com/cyberpoul/CVE-2025-32463-POC
vulncheck_xdb WORKING POC
local
https://github.com/mirchr/security-research
vulncheck_xdb WORKING POC
local
https://github.com/Adonijah01/cve-2025-32463-lab
vulncheck_xdb WORKING POC
local
https://github.com/nelissandro/CVE-2025-32463-Sudo-Chroot-Escape
exploitdb WORKING POC
by Stratascale · textlocallinux
https://www.exploit-db.com/exploits/52352

References (17)

Scores

CVSS v3 9.3
EPSS 0.2572
EPSS Percentile 96.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2025-09-29
VulnCheck KEV 2025-09-29
ENISA EUVD EUVD-2025-19673

Classification

CWE
CWE-829
Status published

Affected Products (18)

sudo_project/sudo < 1.9.17
sudo_project/sudo
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
debian/debian_linux
opensuse/leap
redhat/enterprise_linux
suse/linux_enterprise_desktop
suse/linux_enterprise_desktop
suse/linux_enterprise_real_time
suse/linux_enterprise_real_time
... and 3 more

Timeline

Published Jun 30, 2025
KEV Added Sep 29, 2025
Tracked Since Feb 18, 2026