CVE-2019-14287
HIGH 9.0EPSS 63.8%
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 63.76% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- high · CWE-755
- Published
- 2019-10-17
- Updated
- 2024-08-05
Proof-of-concept exploits (36)
- CMNatic/Dockerized-CVE-2019-142877★ · 2020-02-09
- CashWilliams/CVE-2019-14287-demo1★ · 2020-11-16
- DewmiApsara/CVE-2019-142870★ · 2020-05-12
- FauxFaux/sudo-cve-2019-142871★ · 2019-10-15
- H3xL00m/CVE-2019-142870★ · 2025-06-05
- Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-142870★ · 2021-10-13
- HussyCool/CVE-2019-14287-IT18030372-0★ · 2020-05-12
- M108Falcon/Sudo-CVE-2019-142870★ · 2020-10-04
- MariliaMeira/CVE-2019-142871★ · 2022-10-12
- N3rdyN3xus/CVE-2019-142870★ · 2025-06-05
- NyxByt3/CVE-2019-142870★ · 2025-06-05
- SachinthaDeSilva-cmd/Exploit-CVE-2019-142870★ · 2020-05-11
- ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-142870★ · 2020-05-12
- Sindadziy/cve-2019-142870★ · 2019-11-12
- Sindayifu/CVE-2019-14287-CVE-2014-62710★ · 2020-01-08
- Sp3c73rSh4d0w/CVE-2019-142870★ · 2025-06-05
- Tharana/vulnerability-exploitation3★ · 2020-05-12
- agariy/MyFirstWebShell0★ · 2020-03-18
- axax002/sudo-vulnerability-CVE-2019-142870★ · 2019-12-04
- c0d3cr4f73r/CVE-2019-142870★ · 2025-06-05
- crypticdante/CVE-2019-142870★ · 2025-06-05
- cxzczxzc/sudo-exploit-mitre-attack-poc6★ · 2020-06-08
- edsonjt81/CVE-2019-14287-0★ · 2021-04-25
- filipnyquist/search_vulns0★ · 2025-09-16
- h3x0v3rl0rd/CVE-2019-142870★ · 2025-06-05
- h3xcr4ck3r/CVE-2019-142870★ · 2025-06-05
- huang919/cve-2019-14287-PPT0★ · 2019-11-13
- janod313/-CVE-2019-14287-SUDO-bypass-vulnerability0★ · 2020-05-12
- k4u5h41/CVE-2019-142870★ · 2025-06-05
- lemonadern/poc-cve-2019-142870★ · 2024-10-25
- n0w4n/CVE-2019-1428713★ · 2019-10-15
- n3ov4n1sh/CVE-2019-142870★ · 2025-06-05
- n3rdh4x0r/CVE-2019-142870★ · 2025-06-05
- shallvhack/Sudo-Security-Bypass-CVE-2019-142873★ · 2020-07-23
- thinuri99/Sudo-Security-Bypass-Vulnerability-CVE-2019-14287-0★ · 2020-05-12
- sachinthadesilva/Exploit-CVE-2019-14287