CVE-2025-32463
Sudo: Inclusion of Functionality from Untrusted Control Sphere
As of , CVE-2025-32463 in Sudo is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 29 September 2025
- US federal deadline
- 20 October 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.55Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 1 Metasploit module and 1 Exploit-DB entry
- Fix
- Vendor advice: www.sudo.wsLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
- www.sudo.wsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used…
What the flaw is
Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.
CISA's description
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
The CVE record's description, from mitre
- CVE published
- 30 June 2025
- Assigned by
- mitre
- CVSS
- 9.3 Critical (CVSS 3.1, from the CNA)
- CWE-829
- Inclusion of Functionality from Untrusted Control Sphere
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 52352).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Sudo Chroot 1.9.17 Privilege Escalationexploit module, rank normal
- Exploit-DB: Sudo chroot 1.9.17 - Local Privilege EscalationEDB-ID 52352, 8 July 2025
Sudo: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2021-3156Heap-Based Buffer Overflow | Sudo Sudo | Patch this weekMetasploit module; EPSS 0.99 | 0.99 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org