Vulnerability record · CVE-2023-22809 · published 18 January 2023
CVE-2023-22809: Sudo sudoedit Argument Injection Enables Local Privilege Escalation
Sudo Project · Sudo
Sudo before 1.9.12p2 mishandles extra arguments supplied through the SUDO_EDITOR, VISUAL, and EDITOR environment variables in the sudoedit (-e) feature. A user-specified editor value containing a "--" argument defeats a protection mechanism, letting an attacker append arbitrary file paths to the list of files sudoedit processes. This allows a local user to edit files they should not have write access to, resulting in privilege escalation.
Description
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to root with public exploit code and a very high EPSS score, though it requires an existing local account with sudoedit access.
What it is
Sudo before 1.9.12p2 mishandles extra arguments supplied through the SUDO_EDITOR, VISUAL, and EDITOR environment variables in the sudoedit (-e) feature. A user-specified editor value containing a "--" argument defeats a protection mechanism, letting an attacker append arbitrary file paths to the list of files sudoedit processes. This allows a local user to edit files they should not have write access to, resulting in privilege escalation.
Impact
An attacker with a local account and sudoedit privileges gains the ability to modify arbitrary files with elevated privileges, which can lead to full root compromise. The CVSS vector shows high confidentiality, integrity, and availability impact.
Attack surface
Reached locally by a user who can invoke sudoedit (sudo -e) and control the EDITOR, VISUAL, or SUDO_EDITOR environment variable. No user interaction beyond running the command is required, and the attacker must already hold a local account with sudoedit permission.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.55367, 98.986th percentile) and multiple references are tagged Exploit, including the vendor advisory and a Synacktiv technical writeup, indicating public exploit code exists.
What to do
- Upgrade sudo to 1.9.12p2 or later; affected versions are 1.8.0 through 1.9.12p1.
- Apply vendor patches for Debian, Fedora, Apple macOS, Gentoo, and NetApp products listed in the references.
- Restrict sudoedit (sudo -e) privileges in sudoers to only users who genuinely require them.
- Where sudoedit cannot be removed, avoid granting it on sensitive files and review sudoers rules for broad file-edit permissions.
- Monitor and constrain user-controlled EDITOR, VISUAL, and SUDO_EDITOR environment variables in sudo configurations where possible.
Detection
- Audit sudoers for sudoedit (sudo -e) entries and identify which users and groups can use them.
- Monitor process execution for sudoedit or sudo -e invocations where EDITOR, VISUAL, or SUDO_EDITOR contains a "--" argument or unexpected file paths.
- Alert on writes to sensitive files (for example /etc/sudoers, /etc/passwd, /etc/shadow) originating from sudoedit processes.
- Track sudo version inventory to find hosts still running 1.8.0 through 1.9.12p1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-22809 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22809), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.