CVE-2023-22809
HIGH 7.8EPSS 55.4%
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 55.37% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2023-01-18
- Updated
- 2025-04-04
Proof-of-concept exploits (18)
- http://www.openwall.com/lists/oss-security/2023/01/19/1
- 3yujw7njai/CVE-2023-22809-sudo-POC6★ · 2023-04-06
- AiK1d/CVE-2023-22809-sudo-POC6★ · 2023-04-06
- CKevens/CVE-2023-22809-sudo-POC6★ · 2023-04-06
- Chan9Yan9/CVE-2023-228092★ · 2023-06-20
- D0rDa4aN919/CVE-2023-22809-Exploiter2★ · 2024-09-06
- M4fiaB0y/CVE-2023-228096★ · 2023-02-22
- P4x1s/CVE-2023-22809-sudo-POC6★ · 2023-04-06
- Spydomain/CVE-2023-22809-automated-python-exploits1★ · 2025-08-12
- Toothless5143/CVE-2023-228092★ · 2023-09-03
- asepsaepdin/CVE-2023-228096★ · 2023-07-13
- laxmiyamkolu/SUDO-privilege-escalation0★ · 2024-08-26
- n3m1dotsys/CVE-2023-22809-sudoedit-privesc165★ · 2023-02-15
- n3m1sys/CVE-2023-22809-sudoedit-privesc165★ · 2023-02-15
- pashayogi/CVE-2023-228090★ · 2023-06-25
- spidoman/CVE-2023-22809-automated-python-exploits1★ · 2025-08-12
- stefan11111/rdoedit3★ · 2024-09-06
- ValeuDoamne/CVE-2023-22809