CVE-2025-32462
HIGHCVSS 8.8/10EPSS 3.24%
Last modified
CVE-2025-32462 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.. EPSS estimates a 3.24% chance of exploitation in the next 30 days.
Description
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sudo Project | Sudo | < 1.9.17 |
| Sudo Project | Sudo | 1.9.17 |
References
- https://www.openwall.com/lists/oss-security/2025/06/30/2Mailing List, Third Party Advisory
- https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-hostExploit, Third Party Advisory
- https://www.sudo.ws/releases/changelog/Release Notes
- https://www.sudo.ws/security/advisories/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-32462?
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
How severe is CVE-2025-32462?
CVE-2025-32462 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 3.24% probability of exploitation in the next 30 days.
How do I fix CVE-2025-32462?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-32457The Quantenna Wi-Fi chipset ships with a local control scrip…7.8
- CVE-2025-32458The Quantenna Wi-Fi chipset ships with a local control scrip…7.8
- CVE-2025-32459The Quantenna Wi-Fi chipset ships with a local control scrip…7.8
- CVE-2025-3246An improper neutralization of input vulnerability was identi…7.6
- CVE-2025-32460GraphicsMagick before 8e56520 has a heap-based buffer over-r…9.1
- CVE-2025-32461wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_include…9.9
- CVE-2025-32463Sudo before 1.9.17p1 allows local users to obtain root acces…7.8
- CVE-2025-32464HAProxy 2.2 through 3.1.6, in certain uncommon configuration…6.8
- CVE-2025-32465A stored XSS vulnerability in RSTickets! component 1.9.12 - …8.5
- CVE-2025-32466A SQL injection vulnerability in RSMediaGallery! component 1…6.7
- CVE-2025-32467Use of uninitialized variable for some TDX Module before ver…5.6
- CVE-2025-32468A memory corruption vulnerability exists in the BMPv3 Image …8.8
Are you affected by CVE-2025-32462?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
