Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Alerts on Linux process command lines containing ' -u#' indicative of sudo CVE-2019-14287 exploitation attempts.
- Product
- linux
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2019-10-15
- Updated
- 2026-07-31
ATT&CK techniques
Priv Esc → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Linux process creation events where the command line contains the specific argument pattern ' -u#', consistent with attempts to exploit the sudo vulnerability associated with CVE-2019-14287. Attackers may use malformed or crafted sudo parameters to attempt privilege escalation to higher-privileged execution. The detection relies on Linux process creation telemetry that includes command-line arguments for newly spawned processes.
Reporting behind it
- openwall.comhttps://www.openwall.com/lists/oss-security/2019/10/14/1
- access.redhat.comhttps://access.redhat.com/security/cve/cve-2019-14287
- twitter.comhttps://twitter.com/matthieugarin/status/1183970598210412546
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2019/Exploits/CVE-2019-14287/proc_creation_lnx_exploit_cve_2019_14287.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
id: a1a11aaa-7e59-44d9-9c9e-8d1280189192
status: test
description: This rule flags Linux process creation events where the command line contains the specific argument pattern ' -u#', consistent with attempts to exploit the sudo vulnerability associated with CVE-2019-14287. Attackers may use malformed or crafted sudo parameters to attempt privilege escalation to higher-privileged execution. The detection relies on Linux process creation telemetry that includes command-line arguments for newly spawned processes.
references:
- https://www.openwall.com/lists/oss-security/2019/10/14/1
- https://access.redhat.com/security/cve/cve-2019-14287
- https://twitter.com/matthieugarin/status/1183970598210412546
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2019/Exploits/CVE-2019-14287/proc_creation_lnx_exploit_cve_2019_14287.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2019-10-15
modified: 2022-10-05
tags:
- attack.privilege-escalation
- attack.t1068
- attack.t1548.003
- cve.2019-14287
- detection.emerging-threats
logsource:
product: linux
category: process_creation
detection:
selection:
CommandLine|contains: " -u#"
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: f74107df-b6c6-4e80-bf00-4170b658162b
type: derived