CVE detail
CVE-2019-14287 — CVE-2019-14287
Published 2019-10-17 · Modified 2026-06-17 · Vendor sudo_project · Product sudo · Source nvd
HIGH
severity
CVSS-derived band
0.6376
EPSS probability
exploitation probability, 30d
99.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References