ZeroHour
CyberScooppublished ()ingested @shanvav

Cyber Command, NSA warn to patch decade

criticalVulnerabilityimportance 55
Full article683 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Sudo is found on nearly all Unix and Linux-based operating systems.

NSA National Security Agency
(CyberScoop / Chris Bing)

U.S. intelligence officials are urging American companies and security workers to fix a software flaw that, if exploited, would give attackers deep access to a victim machine.

The vulnerability, which now has a patch, would have allowed unauthorized users to gain what’s known as root privileges on vulnerable hosts as early as 2011 when the flaw was introduced, researchers at the security firm Qualys found. Root access would enable hackers to obtain administrative privileges over a machine, and quietly collect sensitive information.

The vulnerability has existed for 10 years in sudo, a common tool found on nearly all Unix and Linux-based operating systems that generally allows system administrators to give some approved users root privileges.

The flaw affects legacy versions from 1.8.2 to 1.8.31p2 and all default versions from 1.9.0 to 1.9.5p1, according to Qualys.

The National Security Agency warned this week of how prevalent and damaging this issue could be for those who don’t apply patches for the flaw.

It’s “a utility that is available in almost all major linux/unix OS versions,” said Rob Joyce, who has been serving as the NSA’s top intelligence officer in the U.K., where he is responsible for liaising with the U.K.’s Government Communications Headquarters or GCHQ.

Joyce will soon be serving as the NSA’s Cybersecurity Director, as CyberScoop first reported.

The Department of Defense’s Cyber Command, which works on both offensive and defensive security missions for the U.S. government, warned system administrators to pay attention to the sudo flaw as well.

“We recommend applying patches as soon as available. This is a far more dangerous #Sudo vulnerability than seen in the rescent past [sic],” Cyber Command’s Cyber National Mission Force, one of the DOD’s outfits that would be activated when the nation is targeted in cyberspace, warned in a tweet Wednesday.

More Scoops

NSA, National Security Agency, RSA 2019
(Scoop News Group photo)

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that.

Ted Schlein (left), chairman and founding general partner at Ballistic Ventures, talks with former NSA directors (left-right) Gen. Keith Alexander, Gen. Mike Rogers, Gen. Paul Nakasone, and Gen. Tim Haugh at the RSAC 2026 Conference in San Francisco, Calif. (Photo Courtesy of RSAC Conference)

Former NSA chiefs worry American offensive edge in cybersecurity is slipping

President Donald Trump, left, and China’s President Xi Jinping arrive for talks at the Gimhae Air Base, located next to the Gimhae International Airport in Busan on October 30, 2025. Trump and Xi have both been publicly impassive about cyber operations in the past few months.(Photo by ANDREW CABALLERO-REYNOLDS / AFP) (Photo by ANDREW CABALLERO-REYNOLDS/AFP via Getty Images)

While White House demands deterrence, Trump shrugs

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sudo-flaw-cyber-command-nsa-buffer-overflow/