Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-32462

Severity
8.8HIGH
EPSS
21.7%
top 4.25%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 30
Latest updateNov 3

Description

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:NExploitability: 1.1 | Impact: 1.4

Affected Packages4 packages

CVEListV5sudo_project/sudo1.8.81.9.17p1
NVDsudo_project/sudo< 1.9.17+1
Debiansudo< 1.9.5p2-3+deb11u2+3
Ubuntusudo< 1.9.9-1ubuntu2.5+5

🔴Vulnerability Details

5
OSV
sudo vulnerabilities2025-06-30
OSV
sudo vulnerability2025-06-30
OSV
CVE-2025-32462: Sudo before 12025-06-30
CVEList
CVE-2025-32462: Sudo before 12025-06-30
GHSA
GHSA-c5x2-97hm-x895: Sudo before 12025-06-30

💥Exploits & PoCs

1
Exploit-DB
Sudo 1.9.17 Host Option - Elevation of Privilege2025-07-08

📋Vendor Advisories

7
Apple
CVE-2025-32462: macOS Tahoe 26.12025-11-03
Apple
CVE-2025-43334: macOS Tahoe 26.12025-11-03
Red Hat
sudo: LPE via host option2025-06-30
Ubuntu
Sudo vulnerability2025-06-30
Ubuntu
Sudo vulnerabilities2025-06-30
CVE-2025-32462 (HIGH CVSS 8.8) | Sudo before 1.9.17p1 | cvebase.io