Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-3560

KEV EPSS 9.55% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-3560

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不正确
Source: NVD (National Vulnerability Database)
Vulnerability Title
polkit 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
polkit是一个在类 Unix操作系统中控制系统范围权限的组件。通过定义和审核权限规则,实现不同优先级进程间的通讯。 polkit 存在代码问题漏洞,该漏洞源于当请求进程在调用polkit_system_bus_name_get_creds_sync之前断开与dbus-daemon的连接时,该进程无法获得进程的唯一uid和pid,也无法验证请求进程的特权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-polkit polkit 0.119 -

II. Public POCs for CVE-2021-3560

#POC DescriptionSource LinkShenlong Link
1Automatic Explotation PoC for Polkit CVE-2021-3560https://github.com/aancw/polkit-auto-exploitPOC Details
2CVE-2021-3560 Local PrivEsc Exploithttps://github.com/swapravo/polkadotsPOC Details
3a reliable C based exploit and writeup for CVE-2021-3560.https://github.com/hakivvi/CVE-2021-3560POC Details
4polkit exploit script v1.0https://github.com/iSTAR-Lab/CVE-2021-3560_PoCPOC Details
5Nonehttps://github.com/secnigma/CVE-2021-3560-Polkit-Privilege-EsclationPOC Details
6Polkit - Local Privilege Escalation (CVE-2021-3560)https://github.com/curtishoughton/CVE-2021-3560POC Details
7Privilege escalation with polkit - CVE-2021-3560https://github.com/Almorabea/Polkit-exploitPOC Details
8Nonehttps://github.com/AssassinUKG/Polkit-CVE-2021-3560POC Details
9ubuntu new PrivEsc race condition vulnerabilityhttps://github.com/cpu0x00/CVE-2021-3560POC Details
10NYCY_homework_&_meetinghttps://github.com/BizarreLove/CVE-2021-3560POC Details
11Polkit D-Bus Authentication Bypass Exploithttps://github.com/0dayNinja/CVE-2021-3560POC Details
12CVE-2021-3560 (Polkit - Local Privilege Escalation)https://github.com/TomMalvoRiddle/CVE-2021-3560POC Details
13CVE-2021-3560 analysishttps://github.com/chenaotian/CVE-2021-3560POC Details
14Polkit Exploit (CVE-2021-3560), no download capabilty? Copy and paste it!https://github.com/n3onhacks/CVE-2021-3560POC Details
15f4T1H's PoC script for CVE-2021-3560 Polkit D-Bus Privilege Escalationhttps://github.com/f4T1H21/CVE-2021-3560-Polkit-DBusPOC Details
16Nonehttps://github.com/innxrmxst/CVE-2021-3560POC Details
17PolicyKit CVE-2021-3560 Exploit (Authentication Agent)https://github.com/RicterZ/CVE-2021-3560-Authentication-AgentPOC Details
18PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)https://github.com/WinMin/CVE-2021-3560POC Details
19Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalationhttps://github.com/UNICORDev/exploit-CVE-2021-3560POC Details
20Nonehttps://github.com/asepsaepdin/CVE-2021-3560POC Details
21Polkit 0.105-26 0.117-2 - Local Privilege Escalationhttps://github.com/pashayogi/ROOT-CVE-2021-3560POC Details
22CVE-2021-3560 Bypass su - roothttps://github.com/TieuLong21Prosper/CVE-2021-3560POC Details
23Exploitation of the CVE-2021-3560 polkit vulnerabilityhttps://github.com/LucasPDiniz/CVE-2021-3560POC Details
24Nonehttps://github.com/markyu0401/CVE-2021-3560-Polkit-Privilege-EscalationPOC Details
25Part of my cybersecurity thesis consists in exploring and exploiting this vulnerability.https://github.com/Kyyomaa/CVE-2021-3560-EXPLOITPOC Details
26Polkit Exploit (CVE-2021-3560), no download capabilty? Copy and paste it!https://github.com/NeonWhiteRabbit/CVE-2021-3560POC Details
27CVE-2021-3560 (Polkit - Local Privilege Escalation)https://github.com/admin-079/CVE-2021-3560POC Details
28Exploitation Script for CVE-2021-3560https://github.com/arcslash/exploit_CVE-2021-3560POC Details
29This is an exercise built around CVE-2021-3560https://github.com/titusG85/SideWinder-ExploitPOC Details
30Nonehttps://github.com/MandipJoshi/CVE-2021-3560POC Details
31Script Bash -- CVE-2021-3560https://github.com/Antoine-MANTIS/POC-Bash-CVE-2021-3560POC Details
32Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerabilityhttps://github.com/SeimuPVE/CVE-2021-3560_PolkitPOC Details
33polkit privilege escalationhttps://github.com/m4lk3rnel/CVE-2021-3560POC Details
34beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560https://github.com/realatharva15/polkit-CVE-2021-3560_writeupPOC Details
35PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)https://github.com/winmin/CVE-2021-3560POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3560

登录查看更多情报信息。

Same Patch Batch · n/a · 2022-02-16 · 50 CVEs total

CVE-2021-236827.3 HIGHPrototype Pollution
CVE-2021-3760Linux kernel 资源管理错误漏洞
CVE-2022-25265Linux kernel 安全漏洞
CVE-2022-24984JqueryForm.com Jquery Form Builder 安全漏洞
CVE-2022-24985JqueryForm.com Jquery Form Builder 安全漏洞
CVE-2022-22880Jeecg-boot 安全漏洞
CVE-2022-22881Jeecg-Boot SQL注入漏洞
CVE-2022-22885Hutool 安全漏洞
CVE-2022-24983JqueryForm.com Jquery Form Builder 安全漏洞
CVE-2021-3578Sourceforge mbsync 代码问题漏洞
CVE-2021-3773netfilter 信息泄露漏洞
CVE-2021-3752Linux kernel 竞争条件问题漏洞
CVE-2022-22853Sourcecodester Hospital Patient Records Management System 跨站脚本漏洞
CVE-2022-22945VMware NSX-T 操作系统命令注入漏洞
CVE-2022-23804KiCad Eda 缓冲区错误漏洞
CVE-2022-23803KiCad Eda 缓冲区错误漏洞
CVE-2021-21966Texas Instruments Cc3200 SimpleLink Solution Nwp 环境问题漏洞
CVE-2021-21958Hancom Office 缓冲区错误漏洞
CVE-2021-39300Hp Uefi 安全漏洞
CVE-2021-39299Hp Uefi 安全漏洞

Showing top 20 of 50 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-3560

No comments yet


Leave a comment