CVE-2021-3560
published 2022-02-16CVE-2021-3560: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user…
PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
EPSS
22.19%
97.4th percentile
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | policykit-1 | < policykit-1 0.105-31 (bookworm) | policykit-1 0.105-31 (bookworm) |
| msrc | cm1_polkit_0.116-6_on_cbl_mariner_1.0 | — | — |
| polkit_project | polkit | < 0.119 | 0.119 |
| polkit_project | polkit | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-3560 exploits polkit's authentication bypass for D-Bus requests; detect creation of new local users with elevated privileges (UID assignment) without corresponding PAM/sudo authentication events, particularly via accountsservice (org.freedesktop.Accounts). ↗
- →Monitor for the error message 'Error org.freedesktop.Accounts.Error.PermissionDenied: Authentication is required' followed immediately by successful UID insertion, which is a hallmark of the race-condition exploit timing. ↗
- →Linpeas explicitly flags 'Vulnerable to CVE-2021-3560' when polkit is present; monitor for linpeas execution on hosts as a precursor indicator. ↗
- ·The exploit requires accountsservice and gnome-control-center to be installed on the target system; the PoC script checks for these before proceeding. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Red Hat Polkit Incorrect Authorization Vulnerability
cisa·2023-05-12·CVSS 7.8
CVE-2021-3560 [HIGH] CWE-863 Red Hat Polkit Incorrect Authorization Vulnerability
Vulnerability: Red Hat Polkit Incorrect Authorization Vulnerability
Affected: Red Hat Polkit
Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://bugzilla.redhat.com/show_bug.cgi?id=1961710; https://nvd.nist.gov/vuln/detail/CVE-2021-3560
Remediation Due Date: 2023-06-02
Microsoft
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged
vendor_msrc·2022-02-08·CVSS 7.8
CVE-2021-3560 [HIGH] CWE-754 It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to for example create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency
Red Hat
polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()
vendor_redhat·2021-06-03·CVSS 7.8
CVE-2021-3560 [HIGH] CWE-754 polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()
polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentia
Ubuntu
polkit vulnerability
vendor_ubuntu·2021-06-03
CVE-2021-3560 polkit vulnerability
Title: polkit vulnerability
Summary: The system could be made to run programs as an administrator.
Kevin Backhouse discovered that polkit incorrectly handled errors in the
polkit_system_bus_name_get_creds_sync function. A local attacker could
possibly use this issue to escalate privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2021-3560: policykit-1 - It was found that polkit could be tricked into bypassing the credential checks f...
vendor_debian·2021·CVSS 7.8
CVE-2021-3560 [HIGH] CVE-2021-3560: policykit-1 - It was found that polkit could be tricked into bypassing the credential checks f...
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 0.105-31)
bullseye: resolved (fixed in 0.105-31)
forky: resolved (fixed in 0.105-31)
sid: resolved (fixed in 0.105-31)
trixie: resolved (fixed in 0.105-31)
GHSA
GHSA-7c49-j253-wq5r: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the ro
ghsa_unreviewed·2022-02-17
CVE-2021-3560 [HIGH] CWE-754 GHSA-7c49-j253-wq5r: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the ro
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
CVE-2021-3560: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the ro
osv·2022-02-16·CVSS 7.8
CVE-2021-3560 [HIGH] CVE-2021-3560: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the ro
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
VulnCheck
Red Hat Polkit Incorrect Authorization Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-3560 [HIGH] CWE-863 Red Hat Polkit Incorrect Authorization Vulnerability
Red Hat Polkit Incorrect Authorization Vulnerability
Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.
Affected: Red Hat Polkit
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/3c3962d97923; https://vulncheck.com/xdb/e8100379c1b0; https://vulncheck.com/xdb/03fa3b5da68d; https://vulncheck.com/xdb/dd1aeadeb04f; https://vulncheck.com/xdb/0d4f1d0b0a97
Remediation Due: 2023-06-02
No detection rules found.
Exploit-DB
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
exploitdb·2021-06-15·CVSS 7.8
CVE-2021-3560 [HIGH] Polkit 0.105-26 0.117-2 - Local Privilege Escalation
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
---
# Exploit Title: Polkit 0.105-26 0.117-2 - Local Privilege Escalation
# Date: 06/11/2021
# Exploit Author: J Smith (CadmusofThebes)
# Vendor Homepage: https://www.freedesktop.org/
# Software Link: https://www.freedesktop.org/software/polkit/docs/latest/polkitd.8.html
# Version: polkit 0.105-26 (Ubuntu), polkit 0.117-2 (Fedora)
# Tested on: Ubuntu 20.04, Fedora 33
# CVE: CVE-2021-3560
# Source: https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
#!/bin/bash
# Set the name and display name
userName="hacked"
realName="hacked"
# Set the account as an administrator
accountType=1
# Set the password hash for 'password' and password hint
password='$5$WR3c6uwMGQZ/JEZw$OlBVzagNJswkWrKRSuoh/VCrZv183QpZL7sAes
Metasploit
Polkit D-Bus Authentication Bypass
metasploit
Polkit D-Bus Authentication Bypass
Polkit D-Bus Authentication Bypass
A vulnerability exists within the polkit system service that can be leveraged by a local, unprivileged attacker to perform privileged operations. In order to leverage the vulnerability, the attacker invokes a method over D-Bus and kills the client process. This will occasionally cause the operation to complete without being subjected to all of the necessary authentication. The exploit module leverages this to add a new user with a sudo access and a known password. The new account is then leveraged to execute a payload with root privileges.
arXiv
Finding Software Supply Chain Attack Paths with Logical Attack Graphs
arxiv_fulltext·2025-11-14
Finding Software Supply Chain Attack Paths with Logical Attack Graphs
Finding Software Supply Chain Attack Paths with Logical Attack Graphs
Luís Soeiro10009-0003-8609-1352
Thomas Robert10000-0002-4423-5720
Stefano Zacchiroli10000-0002-4576-136X
L. Soeiro et al.
LTCI, Télécom Paris, Institut Polytechnique
de Paris, France
https://www.ip-paris.fr
\luis.soeiro,thomas.robert,stefano.zacchiroli\@telecom-paris.fr
## Abstract
Cyberattacks are becoming increasingly frequent and sophisticated,
often exploiting the software supply chain (SSC) as an attack vector.
Attack graphs provide a detailed representation of the sequence of
events and vulnerabilities that could lead to a successful security
breach in a system. MulVal is a widely used open-source tool for
logical attack graph generation in networked systems. However, its
current lack of support for capturing a
CTF
Paper / README
ctf_writeups
Paper / README
# Paper
> Write-up author: jon-brandy
## STEPS:
> PORT SCANNING
```
┌──(brandy㉿bread-yolk)-[~]
└─$ nmap -p- -sVC 10.10.11.143 --min-rate 1000
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-22 20:39 PDT
Nmap scan report for 10.10.11.143
Host is up (0.077s latency).
Not shown: 64783 closed tcp ports (conn-refused), 749 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.0 (protocol 2.0)
| ssh-hostkey:
| 2048 1005ea5056a600cb1c9c93df5f83e064 (RSA)
| 256 588c821cc6632a83875c2f2b4f4dc379 (ECDSA)
|_ 256 3178afd13bc42e9d604eeb5d03eca022 (ED25519)
80/tcp open http Apache httpd 2.4.37 ((centos) OpenSSL/1.1.1k mod_fcgid/2.3.9)
|_http-generator: HTML Tidy for HTML5 for Linux version 5.7.28
| http-methods:
|_ Potentially risky methods: TRACE
|_http-title: HTTP
CTF
easy / README
ctf_writeups·CVSS 6.0
[MEDIUM] easy / README
---
layout: default
title: Easy Machines
parent: Machines
nav_order: 1
description: "120+ Easy HTB machine writeups with walkthroughs"
permalink: /machines/easy/
---
# HackTheBox Easy Machines - Comprehensive Reference
> Complete catalog of retired HTB Easy machines with OS, key vulnerability, attack path summary, and quality writeup links.
**Total: 100+ Easy Machines** | Updated: April 2026
---
## Quick Navigation
- [Classic / Legacy Machines (2017-2019)](#classic--legacy-machines-2017-2019)
- [2019-2020 Machines](#2019-2020-machines)
- [2021 Machines](#2021-machines)
- [2022 Machines](#2022-machines)
- [2023 Machines](#2023-machines)
- [2024 Machines (Season 4 & 5)](#2024-machines-season-4--5)
- [2025-2026 Machines (Season 6+)](#2025-2026-machines-season-6)
---
## Classic / Legac
CTF
RedPanda / README
ctf_writeups
RedPanda / README
# RedPanda
## Summary
Our Nmap scan reveals SSH and a web server on port `8080`. The web server allows us to search red panda images and view statistics about the number of views an image has. The title of the pages says that the application is made with [Spring Boot](https://spring.io/projects/spring-boot). We fuzz for various vulnerabilities in the "search" field and eventually find a server side template injection (SSTI) vulnerability. Unable to easily get a reverse shell, we write a basic [read–eval–print loop](https://en.wikipedia.org/wiki/Read%E2%80%93eval%E2%80%93print_loop) (REPL) using python: [rps_repl](rps_repl.py). Using this program, we read the contents of the main web application logic file and find a password, which can be used to SSH to the box and get the `user.txt` fla
CTF
Paper / README
ctf_writeups·CVSS 7.8
[HIGH] Paper / README
# Paper - HackTheBox - Writeup
Linux, 20 Base Points, Easy
## Machine
## TL;DR
To solve this machine, we begin by enumerating open services using ```namp``` – finding ports ```22```, ```80``` and ```443```.
***User***: By observing the HTTP response we found ```office.paper``` domain on ```X-Backend-Server``` header, Found it's run behind ```WordPress version 5.2.3``` and by using ```WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts``` exploit we found URL for rocket chat, Inside the chat we found a chatbot, Using ```list``` directory command we found ```scripts``` directory, Using that we found ```run``` command which allows us to run commands, Using that we get a reverse shell as ```dwight``` user.
***Root***: By enumerating we found Polkit running, Using ``
CTF
RedPanda / RedPanda
ctf_writeups
RedPanda / RedPanda
# 📦 RedPanda
Tags: #📦
Related to: [[curl]], [[exiftool]], [[gobuster]], [[nmap]], [[peass]], [[pspy]], [[python]], [[wget]], [[whatweb]]
See also:
Previous: [[HTB]]
## Pre-Engagement
## Linux
```text
10.10.11.170
```
### Information Gathering
#### Basic portscan
nmap 10.10.11.170
```text
PORT STATE SERVICE
22/tcp open ssh
8080/tcp open http-proxy
```
#### Browse http server
http://10.10.11.170:8080/
![[homepage.png]]
#### Identify web technologies
whatweb 10.10.11.170:8080
```text
Title[Red Panda Search | Made with Spring Boot]
```
##### Spring Boot
Spring Boot is a Java framework.
>Vulnerability Assessment => Identify SSTI (Server Side Template Injection)
### Vulnerability Assessment
#### Identify SSTI (Server Side Template Injection)
##### How it works
> Template inje
Checkpoint
14th June – Threat Intelligence Report
blogs_checkpoint·2021-06-14
CVE-2021-21220 14th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Audi and Volkswagen have experienced data breaches that affected 3.3 million customers. Between August 2019 and May 2021, unsecured data was left exposed on the internet by a mutual vendor. During that time, an unauthorized threat actor accesses the data.
Researchers have observed a new wave of DDoS extortion by Fancy Lazarus,
http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.htmlhttp://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1961710https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.htmlhttp://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1961710https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3560
2022-02-16
Published
2023-05-12
Added to CISA KEV
Exploited in the wild