
script de exploit polkit v1.0
script de exploração do polkit
Script automatizado para escalar para root usando o serviço polkit
| Distribuição | Vulnerável? |
|---|---|
| RHEL 7 | Não |
| RHEL 8 | Sim |
| Fedora 20 (ou anterior) | Não |
| Fedora 21 (ou posterior) | Sim |
| Debian 10 (“buster”) | Não |
| Debian testing (“bullseye”) | Sim |
| Ubuntu 18.04 | Não |
| Ubuntu 20.04 | Sim |
ssh localhost
git clone https://github.com/tyleraharrison/CVE-2021-3560_PoC.git
cd CVE-2021-3560_PoC
./polkitRoot.sh
dos2unix polkitRoot.sh porque o GitHub as alterou para CRLF e o Bash não gosta dissoTestado no Ubuntu 20.04
Referência: https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/