ID:11780 - Exploit for Protection mechanism failure in Sudo - CVE-2025-32463

 
Main Vulnerability Database Exploits ID:11780 - Exploit for Protection mechanism failure in Sudo - CVE-2025-32463

ID:11780 - Exploit for Protection mechanism failure in Sudo - CVE-2025-32463

Published: July 18, 2025


Vulnerability identifier: #VU112066
Vulnerability risk: Low
CVE-ID: CVE-2025-32463
CWE-ID: CWE-693
Exploitation vector: Local access
Vulnerable software:
Sudo

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient implementation of security measures when running sudo with -R (--chroot) option. A local user can run arbitrary commands as root, even if they are not listed in the sudoers file.

Note, the vulnerability affects installations with Name Service Switch (NSS) enabled. 


Remediation

Install updates from vendor's website.