Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-32462 PoC — Sudo 安全漏洞

Source
Associated Vulnerability
Title: Sudo 安全漏洞 (CVE-2025-32462)
Description:Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Description
🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers
Readme
# CVE-2025-32462 – sudo -h Privilege Escalation PoC

![MIT License](https://img.shields.io/badge/license-MIT-green)
![PoC](https://img.shields.io/badge/status-proof--of--concept-blue)
![Visitors](https://visitor-badge.laobi.icu/badge?page_id=cyberpoul.CVE-2025-32462-POC)

> 🚨 Local privilege escalation exploit for `sudo` via the `-h/--host` argument  
> Affects systems with `sudo` misconfigurations allowing unintended root access.

---

## 🧠 About

This PoC demonstrates **CVE-2025-32462**, a logic flaw in `sudo` (all versions ≤ 1.9.17),  
where misuse of the `-h` option can bypass RunAs restrictions and allow unintended root command execution.

---

## 📋 Requirements

- Affected `sudo` version: **≤ 1.9.17**
- `sudoers` config includes misconfig like:

  `(ALL, !root) NOPASSWD: ALL`


## 🚀 Usage

- `chmod +x CVE-2025-32462.sh && ./CVE-2025-32462.sh`

- To test a specific command (example: whoami):
 `./CVE-2025-32462.sh whoami`
If the system is vulnerable and misconfigured, this will drop you into a root shell via `sudo -h`. To exit the root shell, type: `exit`


## 🛡️ Mitigation

- Upgrade sudo to 1.9.17p1 or later

- Restrict or disable use of the -h / --host option


## 📚 References

- [NVD Entry – CVE-2025-32462](https://nvd.nist.gov/vuln/detail/CVE-2025-32462)
- [Sudo security advisory](https://www.sudo.ws/security/advisories)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →