In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. CREATE(Triage):(User=admin) CVE-2019-19232 (https://nvd.nist.gov/vuln/detail/CVE-2019-19232)