Polkit D-Bus Authentication Bypass Exploit# Polkit D-Bus Authentication Bypass Exploit
* A vulnerability exists within the polkit system service that can be leveraged by a local, unprivileged attacker to perform privileged operations. In order to leverage the vulnerability, the attacker invokes a method over D-Bus and kills the client process. This will occasionally cause the operation to complete without being subjected to all of the necessary authentication. The exploit module leverages this to add a new user with a sudo access and a known password. The new account is then leveraged to execute a payload with root privileges.
[4.0K] /data/pocs/1e0f5392e410f4c9df5cee698607c0035702a9ad
├── [ 16K] CVE-2021-3560.rb
└── [ 594] README.md
0 directories, 2 files