Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings

Alerts on sudo events with USER values matching patterns linked to CVE-2019-14287 exploit attempts.

FreeReviewedSigma · Critical · v5
Product
linux
Service
sudo
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-10-15
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags sudo activity where the executing USER field matches patterns associated with CVE-2019-14287 exploitation attempts. Attackers may abuse sudo to achieve privilege escalation, and these crafted identifiers are used to trigger vulnerable behavior. It relies on Linux sudo telemetry that includes a USER value for the attempted command execution.

Related detections9 linkedT1068 — drag to rearrange
Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Malicious JuicyPotato Privilege Escalation Execution (UAT-7237)
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Malicious Known Vulnerable Driver Load for BYOVD Attack
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Malicious Qilin EDR Killer BYOVD Driver Load
Malicious Looney Tunables Privilege Escalation Exploit by Kinsing (via process_creation)
Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
Malicious Vulnerable Driver HwRwDrv Loaded for BYOVD
Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings
Pivot detection · T1068 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.