CVE-2019-14287 is a privilege-escalation vulnerability in sudo before version 1.8.28. When a sudoers rule permits execution as arbitrary users via a Runas specification containing ALL, a local user can supply a crafted numeric user ID such as -1 or its unsigned equivalent to sudo’s -u option. Due to the way sudo handled this value in conjunction with underlying setresuid(2) and setreuid(2) semantics, the requested UID was treated specially and the process could remain running with effective UID 0 instead of switching to a non-root target. This allows bypass of sudoers configurations intended to deny root explicitly, such as rules using ALL together with !root, provided ALL appears first in the Runas list. The flaw also causes incorrect target-user logging and can bypass PAM session modules when the specified numeric ID does not correspond to a valid account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository contains a Bash script (sudo.sh) designed to check for and exploit the sudo security bypass vulnerability CVE-2019-14287. The script first determines if the current user has sudo privileges and whether those privileges are unrestricted (ALL) or limited to specific commands. If the user has limited sudo rights and the installed sudo version is older than 1.8.28, the script attempts to exploit the vulnerability by running a permitted command as root using the 'sudo -u#-1' technique. The script provides clear output about the user's sudo status, the version of sudo, and whether the system is vulnerable. The repository also includes a README.md with usage information and a LICENSE file. The exploit is operational and can be used directly or integrated into enumeration tools. The attack vector is local privilege escalation, and the main fingerprintable endpoint is the /etc/sudoers file, which defines sudo permissions.
This repository contains a proof-of-concept Bash script (SudoSecurityBypass.sh) that tests for the Sudo security bypass vulnerability CVE-2019-14287. The exploit targets systems running sudo versions prior to 1.8.28, where a user with limited sudo privileges can escalate privileges by specifying a crafted user ID (specifically, -1 or 4294967295) to execute commands as root, even if root access is explicitly denied in the sudoers configuration. The script first checks the user's sudo permissions, determines the installed sudo version, and if vulnerable, attempts to exploit the flaw by running 'sudo -u#-1 id' or a permitted command as root. The repository also includes a README.md with a detailed description of the vulnerability and usage instructions, and a LICENSE file. The exploit is local and requires shell access to the target system. No network endpoints are involved, but the script interacts with the sudoers configuration file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sudo privilege escalation vulnerability that lets a user bypass Runas restrictions and execute commands as root by supplying UID -1 under affected sudo versions.
A sudo privilege bypass that can allow a user to run commands as root despite Runas rules intended to disallow root, when ALL appears first in the specification.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.