title: Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation id: 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d status: experimental description: | Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation. references: - https://github.com/kh4sh3i/CVE-2025-32463/blob/81bb430f84fa2089224733c3ed4bfa434c197ad4/exploit.sh author: Swachchhanda Shrawn Poudel (Nextron Systems) date: 2025-10-02 modified: 2026-03-31 tags: - attack.privilege-escalation - attack.t1068 - cve.2025-32463 - detection.emerging-threats logsource: category: file_event product: linux detection: selection: TargetFilename|endswith: '/etc/nsswitch.conf' filter_main_legitimate_path: TargetFilename: - '/etc/nsswitch.conf' - '/usr/share/factory/etc/nsswitch.conf' condition: selection and not 1 of filter_main_* falsepositives: - Backup locations level: high