Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-32463 — Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation vulnerability in sudo allowing chroot jail escape via specific sudoers configurations. | Kitploit
Tools/GitHubGitHub/painoob/cve-2025-32463
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingLearning & EducationContainer EscapeBinary ExploitationLabs & Practice
GitHubpainoob/cve-2025-32463

CVE-2025-32463

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation vulnerability in sudo allowing chroot jail escape via specific sudoers configurations.

View Repository
131 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 PoC: CVE-2025-32463 – Sudo chroot Escape Vulnerability

A critical vulnerability affecting sudo versions 1.9.0 to 1.9.17p1, allowing users to escape from chroot and gain access to the real root filesystem.

📌 Description

CVE-2025-32463 is a local privilege escalation vulnerability in sudo that enables users with specific sudoers configurations to escape a chroot jail and access the host system’s root directory.

🔥 Impact

If your /etc/sudoers contains lines such as:

some_user ALL=(ALL:ALL) CHROOT=/path/to/jail /path/to/elf-binary

Then your system is potentially vulnerable.

🧪 Proof of Concept (PoC)

This repository demonstrates a working Proof of Concept to exploit the vulnerability.

⚠️ This PoC is for educational and research purposes only. Use responsibly and only in environments you own or have explicit permission to test.

POC_IMAGE

✅ Requirements

  • Vulnerable version of sudo (1.9.0 to 1.9.17p1)
  • User with chroot sudoers configuration
  • ELF binary permitted in the chroot context

📂 Usage

  1. Clone this repository:
    root@kitploit:~
    git clone https://github.com/your-username/CVE-2025-32463-PoC.git
    cd CVE-2025-32463-PoC
    chmod +x CVE-2025-32463.sh
    ./CVE-2025-32463.sh
    

Read the exploit code and adapt it as needed for your environment.

Execute the PoC under the chrooted sudo environment.

🛡️ Mitigation To protect your systems:

  • Update sudo to version 1.9.17p2 or later
  • Review /etc/sudoers, especially entries involving CHROOT=

📚 References

  • Sudo Security Advisory
  • CVE-2025-32463

⚠️ Disclaimer This project is licensed under the MIT License. This PoC is provided as-is, with no guarantees or warranties. Use at your own risk.

Download Tool