Linux local privilege escalation using authentication bypass vulnerability in polkit CVE-2021-3560

Опубликовано: 29 Сентябрь 2024
на канале: GitHub
33,583
806

Kevin Backhouse walks through a vulnerability in polkit, a widely used system service, here in Ubuntu 20.04, but also used in other distributions such as Fedora and RHEL 8. Using a combination of dbus-send, sleep, and kill, Kevin gets a root shell.

For an in-depth discussion of this vulnerability:
https://github.blog/2021-06-10-privil...