Skip to content

0dayNinja/CVE-2021-3560

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

Polkit D-Bus Authentication Bypass Exploit

  • A vulnerability exists within the polkit system service that can be leveraged by a local, unprivileged attacker to perform privileged operations. In order to leverage the vulnerability, the attacker invokes a method over D-Bus and kills the client process. This will occasionally cause the operation to complete without being subjected to all of the necessary authentication. The exploit module leverages this to add a new user with a sudo access and a known password. The new account is then leveraged to execute a payload with root privileges.

About

Polkit D-Bus Authentication Bypass Exploit

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages