¡¾Îó²îͨ¸æ¡¿Polkit pkexecȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©
Ðû²¼Ê±¼ä 2022-01-260x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-4034 | ʱ ¼ä | 2022-01-25 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | Óû§½»»¥ | ||
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
Polkit£¨PolicyKit£©ÊÇÒ»¸öÓÃÓÚ¿ØÖÆÀàUnixϵͳÖÐϵͳ¹æÄ£È¨ÏÞµÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬ËüΪ·ÇÌØÈ¨Àú³ÌÓëÌØÈ¨Àú³ÌµÄͨѶÌṩÁËÒ»ÖÖÓÐ×éÖ¯µÄ·½·¨¡£¡£¡£¡£¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬ËüÈÏÕæÐÉÌÌØÈ¨Àú³ÌºÍ·ÇÌØÈ¨Àú³ÌÖ®¼äµÄ»¥¶¯£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔÁíÒ»¸öÓû§µÄÉí·ÝÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬£¬ÊÇsudoµÄÌæ»»¼Æ»®¡£¡£¡£¡£¡£
1ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶ÁËÔÚ polkit µÄ pkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034 £¬£¬£¬£¬£¬£¬£¬Ò²³ÆPwnKit)£¬£¬£¬£¬£¬£¬£¬Ëü±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæµÄĬÈÏÉèÖÃÖС£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾µÄ pkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý¼ÆÊý£¬£¬£¬£¬£¬£¬£¬×îÖÕʵÑ齫ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬ÓÕʹ pkexec Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö½«ÍâµØÈ¨ÏÞÌáÉýΪroot¡£¡£¡£¡£¡£
×Ô2009Äê5ÔµĵÚÒ»¸ö°æ±¾£¨Ìá½»c8c3d83£¬£¬£¬£¬£¬£¬£¬"Ìí¼Ópkexec(1)ÏÂÁî"£©ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÖÁÉÙ±£´æÁË12Ä꣬£¬£¬£¬£¬£¬£¬²¢Ó°Ïìµ½ËùÓа汾µÄpkexec¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´ËÎó²îÒ×ÓÚʹÓ㬣¬£¬£¬£¬£¬£¬ÇÒÊÖÒÕϸ½ÚÒѾ¹ûÕæ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑÓйûÕæ¿ÉÓõÄPoC/EXP¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
×Ô2009ÄêÒÔÀ´µÄËùÓÐ Polkit °æ±¾£¨±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæÖУ©¡£¡£¡£¡£¡£
0x02 Çå¾²½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£
²¹¶¡ÏÂÔØÁ´½Ó£º
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
×¢£º
1.UbuntuÒѾΪPolicyKitÍÆËÍÁ˸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ½â¾ö14.04ºÍ16.04 ESM°æ±¾ÒÔ¼°×î½üµÄ18.04¡¢20.04ºÍ21.04°æ±¾ÖеÄÎó²î¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://ubuntu.com/security/notices/USN-5252-2
2.Red HatÒѾΪ Workstation ºÍ Enterprise ²úÆ·ÉϵÄpolkitÌṩÁËÇå¾²¸üС£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://access.redhat.com/security/security-updates/#/security-advisories
3.ÈôÊÇϵͳûÓпÉÓõIJ¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ´Ó pkexec ÖÐɾ³ý SUID λ×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬£¬£¬£¬È磺chmod 0755 /usr/bin/pkexec
0x03 ²Î¿¼Á´½Ó
https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034
https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/
https://access.redhat.com/security/cve/cve-2021-4034
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-01-26 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é
ÍòÀû¹ú¼Ê¹ÙÍø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ