CVE-2019-19232

HIGHCVSS 7.5/10EPSS 3.29%

Last modified

CVE-2019-19232 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. EPSS estimates a 3.29% chance of exploitation in the next 30 days.

Description

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
3.29%

86.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
SudoSudo<= 1.8.29

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-19232?
In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions
How severe is CVE-2019-19232?
CVE-2019-19232 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 3.29% probability of exploitation in the next 30 days.
How do I fix CVE-2019-19232?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-19232?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST