CVE-2023-22809 is a local privilege escalation vulnerability in Sudo's sudoedit (-e) functionality affecting versions 1.8.0 through 1.9.12p1. The flaw arises from improper handling of extra arguments supplied through user-controlled environment variables used to select the editor, specifically SUDO_EDITOR, VISUAL, and EDITOR. If the configured editor string contains additional arguments, including a "--" sequence, an attacker can cause sudoedit to append arbitrary files to the list of files selected for editing, defeating intended protections around which files may be processed. Because sudoedit runs in a privileged context to safely edit files otherwise requiring elevated access, this argument-handling weakness can be abused by a local user to manipulate privileged file edits and escalate privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a small Bash proof-of-concept for CVE-2023-22809 (sudo/sudoedit privilege escalation). Structure: (1) README.md describing the CVE and prerequisite that the user can run sudoedit per `sudo -l`; (2) cve-2023-22809.sh, the only code file; (3) AGPLv3 LICENSE. The script is a local exploit helper: it runs `sudo -l`, checks the current user’s groups (and username) to find an allowed sudo rule containing `sudoedit`, and if found, extracts the sudo command portion into `sudoedit_command`. It then sets the EDITOR environment variable to `vim -- /etc/sudoers` and executes the extracted sudoedit command, attempting to open /etc/sudoers for privileged editing. If sudoedit is not present in the allowed commands, it exits and reports the system as not vulnerable under the required configuration. No network activity is present; the only concrete target endpoint is the privileged file path /etc/sudoers. The intended outcome is privilege escalation by modifying sudoers (e.g., granting the attacker broader sudo access).
This repository contains a Bash proof-of-concept exploit for CVE-2023-22809, a local privilege escalation vulnerability in sudo versions 1.8.0 through 1.9.12p1 on Linux. The main file, 'CVE-2023-22809.sh', checks if the installed sudo version is vulnerable and whether the current user can run sudoedit or 'sudo -e' as root. If so, it opens the /etc/sudoers file for editing, instructing the user to add a line that grants themselves full sudo privileges. After editing, the script attempts to spawn a root shell. The exploit requires local access and appropriate sudoedit privileges. The repository is minimal, containing only the exploit script and a brief README.
This repository contains an automated Python exploit for CVE-2023-22809, a local privilege escalation vulnerability in certain versions of the 'sudo' utility on Linux. The exploit consists of a single Python script ('script.py') and a README.md with detailed usage instructions and background. The script first checks if the installed sudo version is vulnerable, then verifies if the current user has sudoedit privileges as root or ALL. If both conditions are met, it instructs the user to add a line to /etc/sudoers granting full sudo privileges, opens /etc/sudoers with sudoedit, and finally attempts to spawn a root shell. The main fingerprintable endpoint is the '/etc/sudoers' file, which is the target for privilege escalation. The exploit is operational and requires local access with specific sudo privileges. The repository is straightforward, with the exploit logic contained entirely in 'script.py'.
This repository contains a single Metasploit module (modules/exploits/linux/local/sudoedit_bypass_priv_esc.rb) that exploits CVE-2023-22809, a local privilege escalation vulnerability in sudoedit (sudo -e) on Ubuntu 22.04 and 22.10. The exploit abuses improper handling of extra arguments in environment variables (SUDO_EDITOR, VISUAL, EDITOR) to append a line to /etc/sudoers, granting the attacker passwordless root shell access. The module uploads a custom payload (typically a shell) to a writable directory (default: /tmp), modifies /etc/sudoers, and executes the payload as root. The exploit is operational and requires a local shell session on a vulnerable system. The code is written in Ruby and is designed to be run within the Metasploit framework.
This repository contains a Bash script (exploit.sh) and a README.md file. The exploit targets CVE-2023-22809, a local privilege escalation vulnerability in sudo (versions 1.8.0 through 1.9.12p1) on Linux systems. The exploit works by checking if the current user can run sudoedit or sudo -e as root, then abuses the EDITOR environment variable to open /etc/sudoers with elevated privileges. The attacker is prompted to add a line granting themselves full sudo access, after which the script spawns a root shell. The exploit requires the 'nano' editor and sudo to be installed. The README provides background, usage instructions, and references. The main attack vector is local privilege escalation, and the primary fingerprintable endpoint is the /etc/sudoers file.
This repository contains a Bash script (exploit.sh) and a README.md file. The exploit targets CVE-2023-22809, a local privilege escalation vulnerability in sudo versions 1.8.0 to 1.9.12p1. The script automates the exploitation process by first checking if the current user can run 'sudoedit' or 'sudo -e' as root. If so, it opens the /etc/sudoers file using vim, instructing the attacker to add a line that grants themselves full sudo privileges. After editing, the script attempts to spawn a root shell. The attack is local and requires the attacker to have some sudoedit privileges. The only fingerprintable endpoint is the /etc/sudoers file, which is the target for privilege escalation. The exploit is operational, providing a working method to gain root access on vulnerable systems.
This repository contains two exploit scripts (exploit.py in Python and exploit.sh in Bash) targeting CVE-2023-22809, a local privilege escalation vulnerability in sudo (versions 1.8.0 through 1.9.12p1) on Linux. The exploit works by leveraging improper handling of arguments in sudoedit (sudo -e), allowing a user with sudoedit privileges to append arbitrary entries to the list of files processed by sudoedit. Both scripts check for a vulnerable sudo version and appropriate sudoedit permissions, then guide the user to open /etc/sudoers with vim (via sudoedit), add a line granting themselves full sudo privileges, and finally spawn a root shell. The repository also includes a README.md with usage instructions and a LICENSE file. The exploit is operational, requiring local access and specific sudo permissions, and directly targets the /etc/sudoers file for privilege escalation.
This repository contains a Bash exploit script (memek.sh) targeting CVE-2023-22809, a local privilege escalation vulnerability in sudo versions 1.8.0 through 1.9.12p1. The exploit checks if the current user can run sudoedit or sudo -e as root, which is required for exploitation. If exploitable, it opens the /etc/sudoers file using the user's permitted editor, instructing the attacker to add a line granting themselves full sudo privileges. After editing, the script attempts to spawn a root shell. The exploit is operational and requires local access with specific sudo privileges. The only fingerprintable endpoint is the /etc/sudoers file, which is the target for privilege escalation. The repository is minimal, containing only a README and the exploit script.
This repository provides an analysis and two proof-of-concept exploit scripts for CVE-2023-22809, a local privilege escalation vulnerability in sudo (versions 1.8.0 through 1.9.12p1). The vulnerability allows a local attacker with sudoedit privileges to exploit improper handling of environment variables (EDITOR, VISUAL, SUDO_EDITOR) and the "--" argument to edit arbitrary files as root. The repository contains two Bash scripts: - exp_passwd.sh: Exploits the vulnerability to open /etc/passwd for editing as root, allowing the attacker to change the root user's name to their own, thus gaining root access. - exp_sudoers.sh: Exploits the vulnerability to open /etc/sudoers for editing as root, allowing the attacker to add a line granting themselves passwordless sudo access, then spawns a root shell. Both scripts check for a vulnerable sudo version and whether the current user has the necessary sudoedit privileges. The repository also includes detailed markdown documentation (Analysis.md) explaining the vulnerability, affected versions, exploitation steps, and references. The main attack vector is local privilege escalation via manipulation of sensitive system files (/etc/passwd and /etc/sudoers) using sudoedit.
This repository contains a Bash script (exploit.sh) and a README.md file. The exploit targets CVE-2023-22809, a local privilege escalation vulnerability in sudo versions 1.8.0 to 1.9.12p1 on Linux systems. The script checks if the current user can run sudoedit or sudo -e as root. If so, it opens the /etc/sudoers file (using vim) and instructs the user to add a line granting themselves full sudo privileges. After editing, the script attempts to spawn a root shell. The exploit requires local access and appropriate sudo privileges. The main fingerprintable endpoint is the /etc/sudoers file. The repository is a simple proof-of-concept for local privilege escalation and does not include any remote or network-based attack vectors.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.