A critical security vulnerability, tracked as CVE-2025-32463, has been identified in the Sudo command-line utility used across Linux and Unix-like operating systems. This flaw, which carries a CVSS score of 9.3, allows local attackers to execute arbitrary commands as the root user by exploiting the -R (--chroot) option, even if they are not listed in the sudoers file. The vulnerability affects Sudo versions 1.9.14 through 1.9.17, and was officially disclosed by Stratascale researcher Rich Mirch in June 2025. The issue has existed since the release of Sudo version 1.9.14 in June 2023, and impacts the default configuration, meaning no special sudoers rules are required for exploitation. On July 4, 2025, a proof-of-concept exploit was released by Mirch, and additional exploit code has since circulated publicly, increasing the risk of widespread attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-32463 to its Known Exploited Vulnerabilities (KEV) catalog, confirming evidence of active exploitation in the wild. CISA has mandated that federal agencies apply official mitigations or discontinue the use of vulnerable Sudo versions by October 20, 2025. The vulnerability is described as an 'inclusion of functionality from an untrusted control sphere,' which can be leveraged for privilege escalation. Sudo is a critical utility that allows system administrators to delegate root-level privileges to unprivileged users while maintaining an audit trail, making this flaw particularly dangerous. The specific exploitation method involves using the -R option to bypass sudoers restrictions and gain root access. While CISA has not detailed the specific incidents or threat actors involved, the active exploitation and public availability of exploit code have heightened the urgency for remediation. Organizations worldwide are urged to update to Sudo version 1.9.17p1 or later to mitigate the risk. The vulnerability's impact is significant due to the widespread use of Sudo in enterprise and government environments. Security advisories emphasize the need for immediate action to prevent unauthorized privilege escalation and potential compromise of critical systems. The disclosure and subsequent exploitation of this flaw underscore the importance of timely patch management and monitoring for unusual privilege escalation attempts on Linux and Unix systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
ZeroPath published details on 36 security fixes affecting sudo and sudo_logsrvd, including a privilege-escalation flaw later tied to Qualys' CrackArmor exploit chain and a previously unpublished remote code execution path in sudo_logsrvd. The disclosure highlighted that patched versions existed but might not yet be deployed across all Linux distributions.
A GitHub repository published exploit code for CVE-2025-32463, making practical exploitation details publicly accessible. The release represented a new technical escalation between the earlier advisories and the later ZeroPath disclosure.
The Canadian Centre for Cyber Security published advisory AV25-631 covering the Sudo vulnerability and recommended defensive action for affected systems. This reflected broader government-level response and dissemination of mitigation guidance beyond the initial U.S. warning.
CISA issued an alert about a critical vulnerability in the Linux/Unix Sudo utility and warned that it is being actively exploited in the wild. The alert elevated the issue from a routine vulnerability disclosure to an active threat requiring urgent mitigation.
A GitHub repository published a proof-of-concept for CVE-2025-32463 showing a sudo chroot escape that can lead to local privilege escalation. The release made practical exploitation details publicly available before later government exploitation warnings and subsequent exploit-code reporting.
A GitHub repository released a Docker-based proof-of-concept lab for the Sudo vulnerabilities CVE-2025-32462 and CVE-2025-32463, based on Stratascale CRU research. The publication made hands-on exploitation and testing material publicly available well before later government advisories and subsequent exploit-code reporting.
A GitHub repository named mirchr/CVE-2025-32463-sudo-chwoot was published, providing proof-of-concept material for the Sudo chroot elevation-of-privilege flaw CVE-2025-32463. Its publication shows additional public exploit research became available shortly after the earliest repositories on the vulnerability.
A GitHub repository titled Blackash-CVE-2025-32463 was published, indicating public availability of code or technical material related to the Sudo vulnerability CVE-2025-32463. This predates the later Docker lab, subsequent PoCs, and later exploit-code reporting already captured in the timeline.
A GitHub repository at san8383/CVE-2025-32463 was published, indicating public technical material related to the Sudo vulnerability CVE-2025-32463 was available by this date. This appears to predate other known GitHub publications on the flaw.
A GitHub repository at SysMancer/CVE-2025-32463 was published, showing public technical material related to the Sudo vulnerability CVE-2025-32463 was available by this date. It appears to be the earliest GitHub publication currently captured for this flaw.
18 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcezeropath.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.