A city sudo package is old with known public issues, but the rules of engagement ban using public exploits without approval. What is the correct next judgment?
Select an answer to reveal the explanation.
Short Explanation
A juicy old sudo CVE is still not a hall pass past the rules of engagement. Ask for approval or lean on boring misconfigs that are already allowed—professionals do not freelance with public exploits. Contracts beat adrenaline.
Full Explanation
Known vulnerabilities do not supersede rules of engagement. When RoE restricts public exploit use, testers should request explicit approval or continue with permitted manual misconfiguration techniques that often suffice for privilege escalation. Destroying system binaries or releasing unapproved exploits against production violates professional and contractual norms. Document the version finding and the RoE constraint in the report.