cbcvebase.
CVE-2021-3560
published 2022-02-16

CVE-2021-3560: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user…

PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
EPSS
22.19%
97.4th percentile
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debianpolicykit-1< policykit-1 0.105-31 (bookworm)policykit-1 0.105-31 (bookworm)
msrccm1_polkit_0.116-6_on_cbl_mariner_1.0
polkit_projectpolkit< 0.1190.119
polkit_projectpolkit
redhatopenshift_container_platform
redhatvirtualization
redhatvirtualization_host

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/secnigma/CVE-2021-3560-Polkit-Privilege-Esclation/blob/main/poc.sh
  • CVE-2021-3560 exploits polkit's authentication bypass for D-Bus requests; detect creation of new local users with elevated privileges (UID assignment) without corresponding PAM/sudo authentication events, particularly via accountsservice (org.freedesktop.Accounts).
  • Monitor for the error message 'Error org.freedesktop.Accounts.Error.PermissionDenied: Authentication is required' followed immediately by successful UID insertion, which is a hallmark of the race-condition exploit timing.
  • Linpeas explicitly flags 'Vulnerable to CVE-2021-3560' when polkit is present; monitor for linpeas execution on hosts as a precursor indicator.
  • ·The exploit requires accountsservice and gnome-control-center to be installed on the target system; the PoC script checks for these before proceeding.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.