Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern

Alerts on Linux process command lines containing ' -u#' indicative of sudo CVE-2019-14287 exploitation attempts.

FreeReviewedSigma · High · v5
Product
linux
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-10-15
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Linux process creation events where the command line contains the specific argument pattern ' -u#', consistent with attempts to exploit the sudo vulnerability associated with CVE-2019-14287. Attackers may use malformed or crafted sudo parameters to attempt privilege escalation to higher-privileged execution. The detection relies on Linux process creation telemetry that includes command-line arguments for newly spawned processes.

Related detections9 linkedT1068 — drag to rearrange
Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings
Malicious JuicyPotato Privilege Escalation Execution (UAT-7237)
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Malicious Known Vulnerable Driver Load for BYOVD Attack
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Malicious Qilin EDR Killer BYOVD Driver Load
Malicious Looney Tunables Privilege Escalation Exploit by Kinsing (via process_creation)
Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
Malicious Vulnerable Driver HwRwDrv Loaded for BYOVD
Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Pivot detection · T1068 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.