Sploitus

Exploit for Incorrect Authorization in Polkit Project Polkit

githubexploit Β· 2022-02-13

Exploit Code

README15 lines
## https://sploitus.com/exploit?id=F1CDC6B3-63A4-5931-9CAD-8E40F7450674
# CVE-2021-3560-Polkit-DBus
Simple proof of concenpt script for CVE-2021-3560 Polkit D-Bus privilege escalation.
For more information, see original blog post: https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

## Usage
Try running the script again with a different (unregistered) username in case of a fail.
```console
lowprivuser@machine:~$ ./poc.sh 
```

## PoC
![poc](poc.gif)

___─ Written by f4T1H ─___