Multiple public GitHub repositories published proof-of-concept code and lab material for CVE-2025-32463, a local privilege-escalation flaw in sudo that attackers claim can be abused to gain root on vulnerable Linux systems. The repositories describe exploitation paths involving sudo -R and sudo chroot, with one project explicitly advertising root escalation without requiring gcc, lowering the barrier for hands-on abuse and testing.
The disclosures revive long-running concerns around sudo and shell-related privilege boundaries. Earlier sudo hardening addressed environment-variable abuse in Bash-based scripts under CVE-2004-1051, where variables such as PS4 and SHELLOPTS could trigger attacker-controlled command execution, while the Shellshock era showed how incomplete Bash fixes could leave similar parser-driven attack paths exposed. Together, the references show a recurring pattern: privileged execution paths that interact with shell behavior or environment handling remain high-value targets, and newly published PoCs for sudo flaws can quickly turn theoretical local bugs into practical root-compromise risks.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
GitHub repositories publishing proof-of-concept or lab material for CVE-2025-32463, a local privilege-escalation issue involving sudo, began appearing publicly. Multiple repositories published exploit or lab content around the start of July 2025, indicating technical details had become broadly available.
By late September 2014, researchers reported that initial fixes for the Bash Shellshock vulnerability were incomplete and could be bypassed. David A. Wheeler warned that deeper parser changes were likely needed, and Norihiro Tanaka demonstrated a bypass using specially named environment variables.
The sudo project disclosed that versions prior to 1.6.8p10 were vulnerable and released a fix in sudo 1.6.8p10. It also advised administrators to remove PS4 and SHELLOPTS in sudoers or enable env_reset as mitigations.
Tavis Ormandy discovered that sudo's environment sanitization could be bypassed when users ran Bash-based shell scripts via sudo, allowing arbitrary command execution through variables such as PS4 and SHELLOPTS. The issue was assigned CVE-2004-1051.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcearstechnica.com
Open sourcesudo.ws
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.