Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2021-4034 — PoC for cve-2021-4034 | Kitploit
Tools/GitHubGitHub/artemis-mike/cve-2021-4034
Privilege EscalationVulnerability AnalysisExploitationPost-ExploitationPenetration TestingRed Teaming
GitHubartemis-mike/cve-2021-4034

cve-2021-4034

PoC for cve-2021-4034

View Repository
32 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

cve-2021-4034

PoC for cve-2021-4034

Based on the PoC by https://haxx.in: https://haxx.in/files/blasty-vs-pkexec.c. Probably he's https://github.com/blasty?! I don't know.

With a little help from https://github.com/daimoniac

How to use?

Compile cve-2021-4034.c

root@kitploit:~
gcc -Wall cve-2021-4034.c -o cve-2021-4034-exploit

Execute ansible playbook

Change variable hosts in asses_CVE-2021-4034.yml to your usecase!

root@kitploit:~
ansible-playbook -i </path/to/inventory.yml> </path/to/playbooks/>asses_CVE-2021-4034.yml

The playbook copies the exploit to the host, executes it and evaluates whoami on multiple occasions and checks for "root" as return value of the exploit.

On hosts where the task Check result of privilege escalation fails a privilge escalation was successful. In the play recap hosts which don't have failed=0 are vulnerable.

What does it do?

Deep down? I have no idea. Weired memory mashups probably.

What's essential for the operability of this anbible playbook is https://github.com/mike-artemis/cve-2021-4034/blob/main/cve-2021-4034.c#L50. The plain exploit by https://haxx.in/files/blasty-vs-pkexec.c only opens a root-shell and the ansible playbook is stuck in it. Changing the payload of the exploit to

root@kitploit:~
"  static char *a_argv[] = { \"bash\",  \"-c\",  \"whoami\", NULL };\n"

return the current user. The playbook checks the user for privilege escalation and fails the playbook if it happened.

Download Tool