CVE-2025-32463 is a critical local privilege escalation vulnerability in Sudo versions prior to 1.9.17p1, allowing local users to gain root access by manipulating the /etc/nsswitch.conf file within a user-controlled chroot environment. This flaw impacts major Linux distributions including Canonical, Debian, OpenSUSE, Red Hat, and SUSE. Rated with a CVSS score of 7.8 (High) and a FAUCET Risk Score of 95.0, it presents a significant threat due to its low attack complexity, requiring only low privileges and no user interaction to achieve high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, listed on CISA's KEV catalog and Hot List, with public exploit code available in Metasploit and ExploitDB, indicating a high probability of exploitation and widespread community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9.14, < 1.9.17CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
1.9.17CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:* | ||
22.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:* | ||
24.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:* | ||
24.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:24.10:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025AS-2025-004: Sudo
Jul 17, 2025sudo: LPE via chroot option
Jun 30, 2025Sudo before 1.9.17p1 allows local users to obtain root access
Jun 10, 2025