Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-32462-POC — 🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers | Kitploit
Tools/GitHubGitHub/0p5cur/cve-2025-32462-poc
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingRed TeamingPayload Development
GitHub0p5cur/cve-2025-32462-poc

CVE-2025-32462-POC

🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers

View Repository
8597 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-32462 – sudo -h Privilege Escalation PoC

MIT License PoC Visitors

🚨 Local privilege escalation exploit for sudo via the -h/--host argument
Affects systems with sudo misconfigurations allowing unintended root access.


🧠 About

This PoC demonstrates CVE-2025-32462, a logic flaw in sudo (all versions ≤ 1.9.17),
where misuse of the -h option can bypass RunAs restrictions and allow unintended root command execution.


📋 Requirements

  • Affected sudo version: ≤ 1.9.17

  • sudoers config includes misconfig like:

    (ALL, !root) NOPASSWD: ALL

🚀 Usage

  • chmod +x CVE-2025-32462.sh && ./CVE-2025-32462.sh

  • To test a specific command (example: whoami): ./CVE-2025-32462.sh whoami If the system is vulnerable and misconfigured, this will drop you into a root shell via sudo -h. To exit the root shell, type: exit

🛡️ Mitigation

  • Upgrade sudo to 1.9.17p1 or later

  • Restrict or disable use of the -h / --host option

📚 References

  • NVD Entry – CVE-2025-32462
  • Sudo security advisory
Download Tool