
Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized security testing only.
CVE-2025-32463 is a local privilege escalation vulnerability affecting the sudo utility.
It allows a regular user to escalate privileges to root by exploiting the -R option (which sets a custom runtime root directory) together with manipulated NSS configurations.
A successful exploit gives a low-privileged local user full root access, completely breaching the system security boundary.
git clone https://github.com/FreeDurok/CVE-2025-32463-PoC.git
cd CVE-2025-32463-PoC
# Check current user privileges
id
# Run the exploit
./escalate.sh
# Verify escalated privileges
id

✅ Patched: sudo 1.9.17p1 and newer
🚩 Vulnerable: sudo 1.9.14 up to 1.9.17
🕗 Not impacted: Versions before 1.9.14 (the -R feature did not exist)
Upgrade to sudo 1.9.17p1 or later.
Consider limiting or auditing the use of sudo -R through configuration policies.
Use security modules like SELinux or AppArmor to restrict unexpected sudo operations.
This repository is provided for authorized security testing and educational purposes only. Executing these scripts on systems without explicit permission is illegal and violates ethical standards.