HomeSecurityNew PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

A critical vulnerability in the widely used Sudo tool has come under scrutiny after a proof-of-concept exploit was publicly released, causing concern among Linux system administrators worldwide. The vulnerability, CVE-2025-32463, targets the chroot function in Sudo versions 1.9.14 through 1.9.17, allowing local attackers to escalate their privileges to root with minimal effort.

See also: PoC Exploit released for Sudo vulnerability that allows Root access

Sudo chroot

It was discovered by security researcher Rich Mirch and exploits the way Sudo handles user-defined root directories, potentially allowing unauthorized execution of commands as the superuser.

The issue, with a CVSS score of 9.3, is rated critical and highlights ongoing risks in privilege management tools essential to Unix-like operating systems. Reports show active exploitation, prompting urgent calls for a fix from organizations like CISA.

This development comes amid an increase in vulnerabilities related to Sudo, highlighting the tool's persistent role as a prime target for attackers seeking deeper system access

The vulnerability results from improper path resolution of sudo when using the –chroot option, introduced in version 1.9.14 to support user-defined root environments. In affected versions, an attacker can create a malicious /etc/nsswitch.conf within a controlled directory, tricking sudo into loading an arbitrary shared library when evaluating commands.

See also: CISA added Meteobridge vulnerability to the KEV List

New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

This bypasses the limitations of the sudoers, granting root privileges even to users who are not explicitly authorized to escalate privileges. Rich Mirch identified the issue through analysis of sudo's path resolution logic, noting that the implementation of the chroot function creates a vulnerability for local privilege escalation.

The vulnerability does not require network access or elevated privileges, making it particularly dangerous in multi-user environments such as servers and development machines.

Stratascale 's advisory describes how this could lead to a full system compromise, including data extraction or malware deployment. Ubuntu and Red Hat have confirmed that the vulnerability affects their distributions, with patches released in recent updates.

Researcher kh4sh3i 's GitHub repository provides a simple PoC exploit, demonstrating privilege escalation in a controlled environment. Users clone the repository, change to the directory and make the exploit.sh script executable, and run it after verifying their original user ID. The script exploits the chroot option to manipulate the sudo environment, leading to successful privilege escalation as evidenced by the output after execution showing root access.

See also: APT36 attacks BOSS Linux systems via ZIP files

New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

Older versions prior to 1.9.14 remain unaffected due to the lack of chroot support. Immediate mitigation involves updating to Sudo 1.9.17p1 or later, where the feature has been removed and the path resolution bug has been reversed. Administrators should enable AppArmor or SELinux to restrict Sudo functionality and monitor logs for suspicious chroot calls.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS