Back to Database
Status published
Low
CVE-2025-32462
Sudo before 1.9.17p1, when used with a sudoers file that...
Vulnerability Description
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32462
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.sudo.ws/security/advisories/
- https://www.sudo.ws/releases/changelog/
- https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host
- https://www.openwall.com/lists/oss-security/2025/06/30/2
- https://ubuntu.com/security/notices/USN-7604-1
- https://www.secpod.com/blog/sudo-lpe-vulnerabilities-resolved-what-you-need-to-know-about-cve-2025-32462-and-cve-2025-32463/
- https://www.sudo.ws/security/advisories/host_any/
- https://lists.debian.org/debian-security-announce/2025/msg00118.html
- https://explore.alas.aws.amazon.com/CVE-2025-32462.html
- https://bugs.gentoo.org/show_bug.cgi?id=CVE-2025-32462
- https://security-tracker.debian.org/tracker/CVE-2025-32462
- https://www.suse.com/security/cve/CVE-2025-32462.html
- https://access.redhat.com/security/cve/cve-2025-32462
Affected Vendor
Sudo project
View all reports →Affected Software
Sudo
Vulnerable Versions:
1.8.8
Timeline
Official Publish:
June 30th, 2025
Last Modified:
July 14th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N