CVE-2019-14287 is a critical security bypass vulnerability affecting Sudo versions prior to 1.8.28, impacting various Linux distributions like Canonical, Debian, and Red Hat. An authenticated attacker with 'Runas ALL' sudoer privileges can exploit this flaw by crafting a specific user ID, bypassing policy blacklists and PAM modules, potentially gaining root privileges even when explicitly disallowed. This vulnerability carries a CVSS score of 8.8 (HIGH) due to its network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed on the CISA KEV catalog, public exploit code exists on ExploitDB and Nuclei templates, indicating its exploitability. The vulnerability has garnered significant community discussion and media coverage, highlighting its severity and the potential for widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.28CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.