目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-32463 PoC — Sudo 安全漏洞

来源
关联漏洞
标题: Sudo 安全漏洞 (CVE-2025-32463)
Description:Sudo是一款使用于类Unix系统的,允许用户通过安全的方式使用特殊的权限执行命令的程序。 Sudo 1.9.17p1之前版本存在安全漏洞,该漏洞源于使用用户控制目录中的/etc/nsswitch.conf可能导致获取root访问权限。
Description
CVE-2025-32463
介绍
# CVE-2025-32463 Local Privilege Escalation to Root via Sudo chroot in Linux 🛑

Here's a summary of **CVE-2025-32463** without links:

---

### 🔍 Vulnerability Overview

**CVE-2025-32463** is a **local privilege escalation** vulnerability in **Sudo** versions **1.9.14 through 1.9.17**. It abuses the `--chroot` (`-R`) option by manipulating how Sudo handles `nsswitch.conf`. This allows a local attacker to trick Sudo into loading a **malicious shared library**, gaining **root access**, even if they aren't in the `sudoers` file.

---

### ⚠️ Severity

* **CVSS 3.1 Score**: 9.3 (Critical ⚫)
* **Attack Vector**: Local
* **Privileges Required**: None
* **User Interaction**: None

---

### 💀 Exploit

```
sudo git clone https://github.com/B1ack4ash/Blackash-CVE-2025-32463.git
cd CVE-2025-32463
chmod +x CVE-2025-32463.sh
id
./CVE-2025-32463.sh
id
```
![image](https://github.com/user-attachments/assets/4d18ef63-5c0a-4fac-8f82-8c71a9473794)

---

### 🛠️ How the Exploit Works

1. The attacker runs a command like `sudo -R /fake-dir some-command`.
2. Inside `/fake-dir`, they place a fake `etc/nsswitch.conf` that forces Sudo to resolve users or groups via a custom method.
3. This tricks Sudo into loading and executing a **malicious shared library**, leading to **code execution as root**.

---

### 📌 Affected Systems

* Any Linux/Unix-like system running **Sudo 1.9.14 to 1.9.17**
* Systems allowing local shell access (even with no sudo privileges)
* Includes major distributions like Ubuntu, Debian, Red Hat, Fedora, SUSE, Alpine, etc.

---

### ✅ Fixed In

* **Sudo 1.9.17p1** and newer
* Older versions **before 1.9.14** are not affected (they lack the vulnerable chroot feature)

---

### 🛡️ Mitigation Steps

1. **Check your version** using `sudo --version`
2. **Update Sudo** to 1.9.17p1 or latest available version
3. Avoid using `--chroot` option unless necessary
4. Monitor logs for unusual sudo or NSS behavior

---

### 📣 Key Takeaway

Even if a user doesn’t have sudo rights, they can potentially become root by abusing this bug. It’s a critical issue affecting many systems, and it should be patched **immediately**.

---

### ⚠️ Disclaimer

This PoC is provided for educational and research purposes only. Running this on any system without permission is illegal and unethical !!!
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →