Sploitus

Exploit for Inclusion of Functionality from Untrusted Control Sphere in Sudo Project Sudo

githubexploit Β· 2025-08-05

Exploit Code

README54 lines
## https://sploitus.com/exploit?id=3C3D8281-560A-553C-BE53-A35C70F5EAFA
# 🚨 PoC: CVE-2025-32463 – Sudo chroot Escape Vulnerability

> A critical vulnerability affecting `sudo` versions **1.9.0 to 1.9.17p1**, allowing users to escape from `chroot` and gain access to the real root filesystem.

## πŸ“Œ Description

CVE-2025-32463 is a **local privilege escalation** vulnerability in `sudo` that enables users with specific `sudoers` configurations to escape a `chroot` jail and access the host system’s root directory.

### πŸ”₯ Impact

If your `/etc/sudoers` contains lines such as:

some_user ALL=(ALL:ALL) CHROOT=/path/to/jail /path/to/elf-binary

Then your system is potentially **vulnerable**.

## πŸ§ͺ Proof of Concept (PoC)

This repository demonstrates a working Proof of Concept to exploit the vulnerability.

> ⚠️ This PoC is for **educational and research purposes only**. Use responsibly and only in environments you own or have explicit permission to test.

![POC_IMAGE](https://github.com/user-attachments/assets/bd398ccb-527d-4886-84d6-3fc93cf8cc84)

### βœ… Requirements

- Vulnerable version of `sudo` (1.9.0 to 1.9.17p1)
- User with chroot sudoers configuration
- ELF binary permitted in the chroot context

### πŸ“‚ Usage

1. Clone this repository:
   ```bash
   git clone https://github.com/your-username/CVE-2025-32463-PoC.git
   cd CVE-2025-32463-PoC
   chmod +x CVE-2025-32463.sh
   ./CVE-2025-32463.sh
Read the exploit code and adapt it as needed for your environment.

Execute the PoC under the chrooted sudo environment.

πŸ›‘οΈ Mitigation
To protect your systems:
- Update sudo to version 1.9.17p2 or later
- Review /etc/sudoers, especially entries involving CHROOT=

πŸ“š References
- [Sudo Security Advisory](https://www.sudo.ws/security/advisories/)
- [CVE-2025-32463](https://vulners.com/cve/CVE-2025-32463)

⚠️ Disclaimer
This project is licensed under the MIT License. This PoC is provided as-is, with no guarantees or warranties. Use at your own risk.