CVE-2024-32019 affects the Netdata Agent's ndsudo utility. In affected versions, ndsudo is installed as a root-owned SUID executable intended to run only a restricted set of external commands. However, the locations used to resolve those external commands are influenced by the PATH environment variable. Because an unprivileged local user can control PATH, ndsudo may be induced to execute attacker-controlled binaries from writable directories instead of the intended trusted programs. Since ndsudo runs with elevated privileges, this results in execution of arbitrary programs with root permissions and enables local privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
ndsudo binary to execute attacker-controlled programs. Successful exploitation yields arbitrary code execution as root, enabling full host compromise, including modification of system files, installation of persistence, credential theft, disabling security controls, and access to any data on the system.If you can’t patch tonight, do this now.
ndsudo binary where operationally feasible until an upgrade can be applied, but the recommended action is to upgrade to a fixed version.Patch, then assume compromise.
14 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository is a very small local privilege-escalation PoC for CVE-2024-32019 affecting Netdata's SUID helper 'ndsudo'. It contains two files: a README describing the PATH hijacking technique and one Bash exploit script ('pegar en terminal'). The script creates a fake 'nvme' executable in /tmp, prepends that directory to PATH, and invokes '/opt/netdata/usr/libexec/netdata/plugins.d/ndsudo nvme-list'. If the vulnerable ndsudo resolves 'nvme' from PATH while running with elevated privileges, the malicious helper executes as root. The payload then copies /bin/bash into /home/oliver/root_bash_$$, sets mode 4755 to create a persistent SUID root shell, copies /root/root.txt to /home/oliver/root_flag.txt, and launches the shell with 'bash -p' to preserve privileges. The README notes adaptations for hardened lab environments, specifically avoiding nosuid issues by dropping the SUID shell outside /tmp and using bash -p to bypass bash privilege dropping. Overall, this is a real exploit script, not a detector, and it is operational but narrowly tailored to a specific local Linux target layout.
Single-file Python exploit targeting CVE-2024-34070 in Froxlor. The repository contains one script, CVE.py, which uses requests for HTTP interaction, BeautifulSoup is imported but unused, and colorama is used only for console output formatting. The script is interactive: it prompts for a target URL, desired username, and password. It first checks whether the supplied credentials already work against the target login endpoint. If not, it submits a crafted POST request where the loginname field contains a URL-encoded JavaScript stored-XSS payload. That payload, when later executed in an authenticated administrator's browser, extracts the CSRF token from a meta tag and issues a POST request to the Froxlor admin management endpoint admin_admins.php to create a new administrator account with broad privileges. After submission, the script can optionally poll the login endpoint every 10 seconds until the new credentials redirect to admin_index.php, indicating success. Overall, this is a real exploit rather than a detector: it weaponizes a stored XSS into admin account creation on a vulnerable web application.
This repository is a small local privilege-escalation exploit for CVE-2024-32019 affecting Netdata's SUID helper ndsudo on Linux. It contains two files: a README in Spanish describing the technique and one Bash exploit script ('pegar en terminal'). The exploit is not part of a larger framework. The core capability is PATH hijacking. The script writes a malicious executable named 'nvme' into /tmp, prepends /tmp to PATH, and then invokes /opt/netdata/usr/libexec/netdata/plugins.d/ndsudo with the argument 'nvme-list'. If the vulnerable ndsudo resolves and executes nvme from PATH with elevated privileges, the attacker-controlled script runs as root. The payload is straightforward and operational: it uses '#!/bin/bash -p' to preserve privileges, copies /bin/bash into /home/oliver/root_bash_$$, sets mode 4755 to make it a SUID-root shell, copies /root/root.txt into /home/oliver/root_flag.txt, and finally executes the new bash binary with '-p' for an interactive privileged shell. The README notes this was adapted for hardened lab environments by avoiding placement of the SUID shell in /tmp and instead using a home directory path to bypass common nosuid mount restrictions. Repository structure is minimal: one documentation file and one executable Bash script. There are no network callbacks, C2 endpoints, or remote targets; this is purely a local exploit intended for post-compromise privilege escalation on a host already accessible to the attacker.
This repository provides a local privilege escalation exploit for CVE-2024-32019, targeting the ndsudo tool in Netdata Agent (v1.45.0 and below). The exploit leverages an untrusted search path vulnerability, allowing an attacker to execute arbitrary code as root by manipulating the PATH environment variable and placing a malicious binary (nvme) in a writable directory. The repository contains two main bash scripts: - ndsudo_exp.sh: Generates a C source file for a setuid root shell (nvme.c), compiles it, and produces the malicious binary (nvme). - ndsudo_exploit.sh: Downloads the malicious nvme binary from the attacker's server, places it in /tmp, poisons the PATH, and triggers the vulnerable ndsudo binary to execute the attacker's code as root. The README.md provides detailed exploitation steps, including setting up a Python HTTP server to serve the malicious binary and instructions for modifying the exploit script with the attacker's IP address. The exploit is operational and provides a root shell upon successful execution. The attack vector is local, requiring the attacker to have access to the target system to place files and execute scripts. The main fingerprintable endpoints are the attacker's HTTP server (for binary delivery), the /tmp/nvme file, and the path to the ndsudo binary.
This repository contains a Python proof-of-concept exploit for CVE-2024-32019, a local privilege escalation vulnerability in Netdata's 'ndsudo' component. The exploit leverages improper sanitization of the PATH environment variable by ndsudo, allowing a local attacker to hijack execution of allowed binaries (such as 'nvme-list') by placing a malicious executable in the current directory. The script auto-discovers the ndsudo binary in common installation paths, creates a shell script payload that spawns a root shell, adjusts the PATH to prioritize the current directory, and invokes ndsudo to execute the payload as root. After execution, the payload is removed for cleanup. The repository consists of a README.md with usage instructions and poc.py containing the exploit logic. The attack vector is local, requiring shell access to the target system. No network endpoints are involved; all fingerprintable endpoints are file paths related to ndsudo and the payload.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-32019, a privilege escalation vulnerability in Netdata's 'ndsudo' utility. The exploit targets specific vulnerable versions of Netdata on Linux systems. The repository contains four files: a README with detailed instructions, a C source file (example_nvme.c) for the payload, a Bash script (ndsudo_pe.sh) to automate the exploitation on the target, and another Bash script (setup_exploit_server.sh) to set up the attacker's infrastructure (web server and payload compilation). The exploit works by having the attacker host a malicious binary (compiled from the C source) on a web server. The target, after running the provided script, downloads this binary, manipulates the PATH environment variable, and executes 'ndsudo nvme-list', which runs the attacker's code with elevated privileges. The payload establishes a reverse shell to the attacker's machine on port 4444, granting root access. The exploit requires local shell access on the target and the ability to execute ndsudo. The repository is well-structured for PoC use, with clear separation between payload, exploitation script, and infrastructure setup.
This repository provides a proof-of-concept (POC) exploit for a local privilege escalation vulnerability in the 'ndsudo' utility bundled with Netdata. The exploit leverages a PATH injection technique: the attacker creates a malicious script (poc.py) named after an allowed command (e.g., 'nvme'), places it in a directory (e.g., /tmp/nvme), and prepends this directory to the PATH environment variable. When 'ndsudo' is invoked with the allowed command, it executes the attacker's script as root. The provided Python payload sets the process's UID and GID to 0 and spawns a root shell. The repository consists of a README.md with detailed exploitation steps and a simple Python script (poc.py) that forms the core of the exploit. The exploit requires local shell access, Python3, and the ability to execute 'ndsudo' on the target system.
This repository provides a local privilege escalation exploit for CVE-2024-32019, targeting Netdata's 'ndsudo' SUID helper on Linux systems. The exploit leverages a PATH hijacking vulnerability, allowing a local attacker to execute arbitrary binaries as root by placing a malicious binary (named 'nvme') in a directory earlier in the PATH. The repository contains four files: a Bash exploit script (CVE-2024-32019.sh), a C payload (payload.c) that spawns a root shell, a README.md with detailed usage instructions and background, and a .gitignore. The exploit script locates the vulnerable 'ndsudo' binary, ensures the payload is present and executable, then manipulates the PATH and invokes 'ndsudo' to execute the attacker's payload as root. The README provides compilation and usage steps, including example commands for downloading the exploit and payload via HTTP. The exploit is operational, providing a working root shell if the target is vulnerable and properly configured.
This repository contains a single C source file (CVE-2024-32019.c) that implements a local privilege escalation exploit. The code sets the group and user ID to 0 (root) and then executes /bin/bash, effectively spawning a root shell if the binary is run with sufficient privileges. There are no network or remote attack vectors; this is a local exploit. The repository also includes a README (in Chinese, stating it is for vulnerability remediation assistance only) and an MIT license. The exploit is operational, providing a working payload for privilege escalation on vulnerable systems. The only fingerprintable endpoint is the use of /bin/bash as the shell to be executed with root privileges.
This repository contains a single Metasploit module (Ruby file) that exploits a local privilege escalation vulnerability (CVE-2024-32019) in the Netdata Agent's 'ndsudo' utility on Linux systems (v1.45.0 and below). The exploit leverages an untrusted search path issue: when ndsudo is invoked to run a command (such as 'nvme-list'), it searches for the required binary (e.g., 'nvme') in the directories listed in $PATH, trusting the first occurrence. The module uploads a malicious 'nvme' binary to a writable directory (default: /tmp), modifies the $PATH to prioritize this directory, and then executes ndsudo, causing it to run the attacker's payload as root. The module is operational, providing privilege escalation if the target is vulnerable and the attacker has a session. The only file in the repository is the Metasploit exploit module, written in Ruby, and it is structured according to Metasploit conventions.
This repository provides a working exploit for CVE-2024-32019, targeting the Netdata ndsudo utility on Linux systems. The exploit consists of a Go program (poc.go) that, when executed as root, sets the SUID bit on /bin/bash, enabling privilege escalation. The bash script (exploit.sh) automates the attack: it starts a Python HTTP server to serve the payload (nvme), generates a payload.sh script that downloads and executes the payload on the target, and instructs the attacker to have the target fetch and run this script. The README provides clear build and usage instructions. The main attack vector is a combination of network (HTTP file delivery) and local privilege escalation. The exploit is operational, requiring some manual steps but providing a reliable method to escalate privileges if the target is vulnerable.
This repository contains a Python exploit script (CVE-2024-32019-dbs.py) targeting CVE-2024-32019, a local privilege escalation vulnerability in the Netdata Agent's 'ndsudo' SUID binary. The exploit automates the following steps: (1) compiles a C payload that spawns a root shell, (2) uploads the payload to a writable directory on the target via SSH, (3) manipulates the PATH environment variable to prioritize the malicious binary, and (4) triggers 'ndsudo' to execute the payload as root, resulting in a root shell. The script includes checks for the presence and permissions of 'ndsudo', uploads the payload using SFTP, and provides an interactive root shell if successful. The repository also includes a README.md with a technical summary, manual exploitation steps, affected versions, and references. The exploit requires SSH access to the target and is operational, providing a working local privilege escalation to root on vulnerable Netdata Agent installations.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-32019, a local privilege escalation vulnerability in Netdata's 'ndsudo' binary due to an untrusted search path. The exploit consists of a C source file ('exploit.c') that, when compiled and executed via a manipulated PATH, spawns a root shell and attempts to connect back to an attacker-controlled machine using a reverse shell on TCP port 9001. The README.md details affected Netdata versions, compilation instructions, and exploitation steps, including the use of PATH manipulation to trigger the vulnerability. The exploit targets Linux systems running vulnerable Netdata versions and requires local access to upload and execute the payload. Notable endpoints include the target binary path, the bash shell, and a customizable reverse shell IP/port.
This repository contains a local privilege escalation proof-of-concept (POC) targeting the 'ndsudo' utility bundled with Netdata (see advisory GHSA-pmhq-4cxq-wj93). The exploit leverages a PATH hijacking technique: the attacker compiles a malicious binary ('nvme' from 'poc.c') that spawns a root shell, places it in a writable directory (e.g., /tmp), and prepends this directory to their PATH. When 'ndsudo' is invoked with a command like 'nvme-list', it resolves and executes the attacker's binary as root, granting a root shell. The repository consists of a README.md with detailed exploitation steps and a simple C payload (poc.c) that sets UID/GID to 0 and executes /bin/bash. The exploit requires local shell access and the ability to upload and execute files. No network endpoints are involved; the attack vector is purely local.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in the Netdata ndsudo plugin that, when misconfigured, allows privilege escalation to root.
A privilege escalation vulnerability in the Netdata ndsudo plugin, allowing arbitrary code execution as root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.