parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Score: 1.8
Priority: P4 - Informational (Low)
Score: 0.00049
Percentile:
0.15087
CVSS v3.1 Score: 7.8
Severity: HIGH