← back
CVE-2021-3560

CVE-2021-3560

CVSS 7.8 HIGHEPSS 22.2%● KEVCWE-863
In short

Polkit, a system tool that controls who can perform sensitive tasks, can be tricked into allowing unprivileged users to gain root access. An attacker could exploit this to create admin accounts or take full control of the system.

Technical detail

CVE-2021-3560 is a privilege escalation vulnerability in polkit's D-Bus credential validation logic (CWE-863). An unprivileged local attacker can bypass authorization checks through crafted D-Bus requests, gaining root privileges without proper authentication. This affects confidentiality, integrity, and availability of the system.

Summary generated and translated by AI from the official description.
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · polkit
public PoCs found34
githubgithub.com/Almorabea/Polkit-exploit127githubgithub.com/secnigma/CVE-2021-3560-Polkit-Privilege-Esclation124githubgithub.com/RicterZ/CVE-2021-3560-Authentication-Agent116githubgithub.com/swapravo/polkadots82githubgithub.com/hakivvi/CVE-2021-356040githubgithub.com/winmin/CVE-2021-356025githubgithub.com/AssassinUKG/Polkit-CVE-2021-356024githubgithub.com/UNICORDev/exploit-CVE-2021-356012githubgithub.com/0dayNinja/CVE-2021-35609githubgithub.com/chenaotian/CVE-2021-35609githubgithub.com/aancw/polkit-auto-exploit5githubgithub.com/BizarreLove/CVE-2021-35602githubgithub.com/Kyyomaa/CVE-2021-3560-EXPLOIT2githubgithub.com/cpu0x00/CVE-2021-35602githubgithub.com/LucasPDiniz/CVE-2021-35602githubgithub.com/Jeanback1/CVE-2021-3560-exploit0githubgithub.com/yutasato88/CVE-2021-3560-PolkitPrivilegeEsclation0githubgithub.com/adakoifman/CVE-2021-35600githubgithub.com/iSTAR-Lab/CVE-2021-3560_PoC0githubgithub.com/curtishoughton/CVE-2021-35600githubgithub.com/admin-079/CVE-2021-35600githubgithub.com/asepsaepdin/CVE-2021-35600githubgithub.com/pashayogi/ROOT-CVE-2021-35600githubgithub.com/TieuLong21Prosper/CVE-2021-35600githubgithub.com/markyu0401/CVE-2021-3560-Polkit-Privilege-Escalation0githubgithub.com/arcslash/exploit_CVE-2021-35600githubgithub.com/titusG85/SideWinder-Exploit0githubgithub.com/MandipJoshi/CVE-2021-35600githubgithub.com/Antoine-MANTIS/POC-Bash-CVE-2021-35600githubgithub.com/SeimuPVE/CVE-2021-3560_Polkit0githubgithub.com/realatharva15/polkit-CVE-2021-3560_writeup0exploitdbwww.exploit-db.com/exploits/50011unverifiedcve_referencepacketstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.htmlunverifiedcve_referencepacketstormsecurity.com/files/172836/polkit-Authentication-Bypass.htmlunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →