CVE-2025-32463
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Published
- Jun 30, 2025
- Updated
- Feb 26, 2026
- Assigning CNA
- mitre
- Evidence observed
- Jul 8, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Sources
70🛡️ Proof of Concept (PoC) for CVE-2025-32463 - Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.
- CVE-2025-32463Exploit
CVE-2025-32463
- CVE-2025-32463_exploitExploit
Local privilege escalation exploit for sudo 1.9.14-1.9.17 that abuses CVE-2025-32463 chroot handling, planting a malicious NSS library constructor to spawn a root shell for any local user.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.