
# Automatisiertes Privilege-Escalation-Skript, das CVE-2021-3560 in polkit ausnutzt, um Root-Zugriff auf anfällige Linux-Distributionen zu erlangen.
polkit-Exploit-Skript
Automatisiertes Skript zur Root-Rechteausweitung mithilfe des polkit-Dienstes
| Distribution | Anfällig? |
|---|---|
| RHEL 7 | Nein |
| RHEL 8 | Ja |
| Fedora 20 (oder früher) | Nein |
| Fedora 21 (oder später) | Ja |
| Debian 10 (“buster”) | Nein |
| Debian testing (“bullseye”) | Ja |
| Ubuntu 18.04 | Nein |
| Ubuntu 20.04 | Ja |
ssh localhost
git clone https://github.com/tyleraharrison/CVE-2021-3560_PoC.git
cd CVE-2021-3560_PoC
./polkitRoot.sh
dos2unix polkitRoot.sh geändert werden, da GitHub sie in CRLF umgewandelt hat und Bash das nicht magGetestet unter Ubuntu 20.04
Referenz: https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/