Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation.
Detection logic
selection
TargetFilename|endswith: /etc/nsswitch.conffilter_main_legitimate_path
TargetFilename:
- /etc/nsswitch.conf
- /usr/share/factory/etc/nsswitch.confCondition
selection and not 1 of filter_main_*Raw YAML
title: Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
id: 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d
status: experimental
description: |
Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463.
This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations.
When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment,
potentially leading to arbitrary code execution and privilege escalation.
references:
- https://github.com/kh4sh3i/CVE-2025-32463/blob/81bb430f84fa2089224733c3ed4bfa434c197ad4/exploit.sh
author: Swachchhanda Shrawn Poudel (Nextron Systems)
date: 2025-10-02
modified: 2026-03-31
tags:
- attack.privilege-escalation
- attack.t1068
- cve.2025-32463
- detection.emerging-threats
logsource:
category: file_event
product: linux
detection:
selection:
TargetFilename|endswith: '/etc/nsswitch.conf'
filter_main_legitimate_path:
TargetFilename:
- '/etc/nsswitch.conf'
- '/usr/share/factory/etc/nsswitch.conf'
condition: selection and not 1 of filter_main_*
falsepositives:
- Backup locations
level: highFalse positives
- Backup locations
References
Similar rules
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
criticalwindows · Shares T1068
Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator
highlinux · Shares T1068
Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator
highlinux · Shares T1068
Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800
highlinux · Shares T1068