Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-3560 — Повышение привилегий через race condition в polkit | Kitploit
Tools/GitHubGitHub/adakoifman/cve-2021-3560
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingRed TeamingBinary Exploitation
GitHubadakoifman/cve-2021-3560

CVE-2021-3560

Повышение привилегий через race condition в polkit

View Repository
23 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-3560

Privilege escalation via race condition in polkit.

Vulnerability Description

CVE-2021-3560 is a race condition in polkit that allows an unauthenticated local user to gain root privileges. The vulnerability exists in the way polkit handles D-Bus errors when a connection is terminated.

Timing Determination

To determine the optimal timing, run the command:

time dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:testuser string:"Test User" int32:1

The code uses a range of half the real time ± 0.003.

Why is timing important?

  • If the process is killed too early, the request will not be sent
  • If killed too late, polkit will have time to check authorization and reject it
  • You need to hit the "golden window" when polkit has already received the request but has not yet checked authorization

How does the exploit work?

  • A D-Bus request is sent to create a user with the parameter int32:1 (adding to the wheel group)
  • The request is interrupted mid-way (race condition)
  • Polkit fails to complete the authorization check
  • D-Bus cannot find the sender
  • Polkit incorrectly handles the error and assigns UID = 0 (root)
  • The user is created without authentication
  • A request is sent to set a password for the new user (with the same timing)

Success Statistics

  • The user can be created within 1-2 attempts
  • Setting the password requires more attempts
  • 100 iterations give a high probability of success

If the exploit does not work, try:

  • Expand TIMING_RANGE in the code
  • Run the script several times
  • Make sure you are in an SSH session (not in a graphical one)
Download Tool