CVE-2019-18684 describes a race condition vulnerability in Sudo versions up to 1.8.29, potentially allowing a local user with write access to file descriptor 3 of the sudo process to escalate privileges to root. This high-severity vulnerability (CVSS 7.0) requires specific conditions, including write access to a sensitive file descriptor, and its practical exploitability has been disputed due to Linux /proc filesystem behavior. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.29CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.