
🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers
🚨 Local privilege escalation exploit for
sudovia the-h/--hostargument
Affects systems withsudomisconfigurations allowing unintended root access.
This PoC demonstrates CVE-2025-32462, a logic flaw in sudo (all versions ≤ 1.9.17),
where misuse of the -h option can bypass RunAs restrictions and allow unintended root command execution.
Affected sudo version: ≤ 1.9.17
sudoers config includes misconfig like:
(ALL, !root) NOPASSWD: ALL
chmod +x CVE-2025-32462.sh && ./CVE-2025-32462.sh
To test a specific command (example: whoami):
./CVE-2025-32462.sh whoami
If the system is vulnerable and misconfigured, this will drop you into a root shell via sudo -h. To exit the root shell, type: exit
Upgrade sudo to 1.9.17p1 or later
Restrict or disable use of the -h / --host option