Citing evidence of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a severe security issue affecting the Sudo command-line application for Linux and Unix-like operating systems to its Known Exploited Vulnerabilities (KEV) database on Monday.
Specifically, Sudo versions before 1.9.17p1 are vulnerable to CVE-2025-32463 (CVSS score: 9.3). Rich Mirch, a researcher at Stratascale, revealed it in July 2025.
According to CISA, Sudo incorporates functionality from an untrusted control sphere vulnerability. Due to this flaw, a local attacker may be able to use sudo’s -R (–chroot) option to execute any command as root, even if it isn’t specified in the sudoers file.
At this time, it is unknown how the vulnerability is being used in actual assaults and who might be responsible. Four other defects have also been added to the KEV inventory read more about CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
