CVE-2019-14287General(canonical / debian_linux)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-755

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • element_software_management_node
  • enterprise_linux
  • enterprise_linux_desktop

Threat summary

  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 6 classified signals
  • Exploit: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-02); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Products
debian_linuxelement_software_management_nodeenterprise_linuxenterprise_linux_desktopenterprise_linux_eusenterprise_linux_serverenterprise_linux_server_ausenterprise_linux_server_tusenterprise_linux_workstationfedora

30 versions affected across 15 products

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-01-27: 1Mentions · 2026-02-24: 1Mentions · 2026-03-13: 1Mentions · 2026-04-02: 2Mentions · 2026-04-07: 1Mentions · 2026-08-19: 1Mentions · 2026-09-08: 1Technical Details · 2026-03-13: 1Technical Details · 2026-08-19: 101-2702-2403-1304-0204-0708-1909-08
Signal classification3 categories
General
675.0%
Exploit
112.5%
Disclosure
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-271
General1
2026-02-241
General1
2026-03-131
Exploit1
2026-04-022
General2
2026-04-071
General1
2026-08-191
Disclosure1
2026-09-081
General1
Full discourse8 posts
  • インチキ・サイバー用語集@InchkeyCyber
    Disclosure

    (解説) 特定の旧バージョンの sudo には、sudoers 設定で ALL と !root を組み合わせた場合に、-1 や 4294967295 を指定することで root 権限でコマンドを実行できてしまう脆弱性が存在していました。これは広く知られる CVE-2019-14287 に該当します。

    Post summary

    The text explains how older sudo versions can be abused to gain root privileges by combining ALL and !root in sudoers, identifying CVE‑2019‑14287.

    0100054
    104 followersView on X
  • ANTHONY@CYB3RW4RFARE
    Exploit

    In this quick lab, I gained root privileges by exploiting an outdated sudo version. To check the version of sudo, you can use the command "sudo -V." If the version is earlier than 1.8.28, you can utilize CVE-2019-14287 to gain root access with a single command. https://t.co/YCR64YVwcR

    Post summary

    The post briefly describes how exploiting CVE-2019-14287 in older sudo versions allows a single-command privilege escalation to root, without providing detailed exploit code or patch guidance.

    0001046
    510 followersView on X
  • Havij@_havij
    General

    [Agent Sudo] HTTP User-Agent Enumeration, Hidden Data Extraction & CVE-2019-14287 Privilege Escalation Link: https://meetcyber.net/agent-sudo-http-user-agent-enumeration-hidden-data-extraction-cve-2019-14287-privilege-f57ec13095ef #privilegeescalation #cve201914287 https://t.co/S6Z66DIDvt

    Post summary

    The tweet references an exploit method for CVE‑2019‑14287 involving HTTP User‑Agent enumeration and hidden data extraction, but it lacks any code, patch information, or evidence of real‑world use.

    0000029
    27 followersView on X
  • Sun4lower@LittleSun4lower
    General

    I just completed Sudo Security Bypass room on TryHackMe! A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series https://tryhackme.com/room/sudovulnsbypass?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #Tryhackme #Learning

    Post summary

    The post notes completion of a TryHackMe tutorial room focused on CVE‑2019‑14287, but provides no technical, exploit, or patch details.

    0000028
    5 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Sudo Security Bypass room on TryHackMe! A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series https://tryhackme.com/room/sudovulnsbypass?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe tutorial room for CVE-2019-14287, offering a learning resource but providing no technical exploitation, patch, or contextual details.

    0000023
  • VibeQuest@BaraniBr443638
    General

    I just completed Sudo Security Bypass room on TryHackMe! A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series https://tryhackme.com/room/sudovulnsbypass?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=61eac99b5af18f0042650fad #tryhackme via @tryhackme

    Post summary

    A user posted that they completed a TryHackMe tutorial room about CVE-2019-14287, including a link to the room, but the post does not provide any PoC, exploit code, patch information, or technical vulnerability details.

    0000030
    6 followersView on X
  • Jason@flarestartcom
    General

    Yet Another CVE analysis (CVE-2019-14287) via http://Dev.to https://flarestart.com/article/yet-another-cve-analysis-cve-2019-14287-20260223 #DevNews #Security #Tutorial https://t.co/HY2KSGRol6

    Post summary

    The tweet merely links to an article titled 'Yet Another CVE analysis (CVE-2019-14287)' without providing additional technical or exploit information.

    000002
    10 followersView on X
  • Jayesh Verma@JayeshV88153533
    General

    I just completed Sudo Security Bypass room on TryHackMe. A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series https://tryhackme.com/room/sudovulnsbypass?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=684d724b80fe1af75347f3e4 #tryhackme via @tryhackme

    Post summary

    The user references completing a TryHackMe tutorial room on CVE‑2019‑14287, but no PoC, exploit details, patch, or technical specifics are provided.

    0000031
    16 followersView on X
CPE platform detail47 entries

47 of 47 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux12.04--
OScanonicalubuntu_linux14.04--
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux19.04--
OSdebiandebian_linux10.0--
OSdebiandebian_linux8.0--
OSdebiandebian_linux9.0--
OSfedoraprojectfedora29--
OSfedoraprojectfedora30--
OSfedoraprojectfedora31--
Appnetappelement_software_management_node---
OSopensuseleap15.0--
OSopensuseleap15.1--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_desktop7.0--
OSredhatenterprise_linux_eus7.5--
OSredhatenterprise_linux_eus7.6--
OSredhatenterprise_linux_eus7.7--
OSredhatenterprise_linux_eus8.1--
OSredhatenterprise_linux_eus8.2--
OSredhatenterprise_linux_eus8.4--
OSredhatenterprise_linux_server5.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server7.0--
OSredhatenterprise_linux_server_aus6.5--
OSredhatenterprise_linux_server_aus6.6--
OSredhatenterprise_linux_server_aus7.2--
OSredhatenterprise_linux_server_aus7.3--
OSredhatenterprise_linux_server_aus7.4--
OSredhatenterprise_linux_server_aus7.6--
OSredhatenterprise_linux_server_aus7.7--
OSredhatenterprise_linux_server_aus8.2--
OSredhatenterprise_linux_server_aus8.4--
OSredhatenterprise_linux_server_tus7.2--
OSredhatenterprise_linux_server_tus7.3--
OSredhatenterprise_linux_server_tus7.4--
OSredhatenterprise_linux_server_tus7.6--
OSredhatenterprise_linux_server_tus7.7--
OSredhatenterprise_linux_server_tus8.2--
OSredhatenterprise_linux_server_tus8.4--
OSredhatenterprise_linux_workstation6.0--
OSredhatenterprise_linux_workstation7.0--
Appredhatopenshift_container_platform4.1--
Appredhatvirtualization4.2--
Appsudo_projectsudo---

Explore more