A publicly available PoC exploit has been released for CVE-2025-32463, a local privilege escalation (LPE) vulnerability in the Sudo tool that can grant root access under certain settings.
See also: CISA added Sudo vulnerability to KEV List

Security researcher Rich Mirch is credited with identifying the vulnerability, while a working PoC and usage guide have been published in an open GitHub repository, accelerating the need for a fix in Linux environments that rely on Sudo's chroot functionality
The vulnerability is in the way Sudo handles chroot-related call paths and environments when executing commands with elevated privileges. Under certain circumstances, a low-privileged user can exploit the chroot feature to move outside the restricted environment and execute commands as root. This turns a typical LPE scenario into a full-scale system compromise when Sudo policies allow chroot.
See also: Sudo vulnerabilities allow root access on Linux distributions

The PoC shows a simple exploitation flow: verify the version of sudo on the target, run the exploit script, and observe the effective UID/GID to root. In test screenshots, the user transitions from uid=1001 to uid=0 after the script is run, confirming successful escalation. The project explicitly categorizes the issue as “Local Privilege Escalation to Root via Sudo chroot on Linux,” emphasizing that the exploit relies on local account access and specific Sudo settings that allow chroot execution.
The immediate fix is to upgrade Sudo to version 1.9.17p1 or later on all affected systems. Where upgrades must be scheduled, administrators should enforce Sudo to deny or severely restrict chroot use and enforce the principle of least privilege. Mandatory access control frameworks such as AppArmor or SELinux can further restrict Sudo behavior and limit abuse paths during change windows.
See also: Microsoft: Linux 'Sudo' in Windows Server 2025

From a detection perspective, defenders should watch for anomalous sudo calls that point to chroot or unusual working directories, correlate privilege transitions (uid changes to 0) from non-standard shells or paths, and alert for rapid “id → exploit → id” sequences commonly observed during exploit testing.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
