Cybersecurity and Information Warfare

New Sudo vulnerability allows local privilege escalation, urgent patches needed.

A critical vulnerability (CVE-2025-32463) in the widely used Sudo utility allows local attackers to escalate privileges to root level, impacting versions 1.9.14 through 1.9.17. Discovered by researcher Rich Mirch, the flaw exploits the chroot feature, enabling unauthorized command execution, and has a CVSS score of 9.3. Active exploitation has been reported, prompting urgent patching calls from organizations such as CISA, with patches already rolled out for affected distributions like Ubuntu and Red Hat. This incident underscores the ongoing risks associated with privilege management tools in multi-user environments, emphasizing the importance of promptly addressing vulnerabilities to protect systems from potential breaches and data exfiltration.

Share

Leave a Reply

Your email address will not be published. Required fields are marked *