¡¾Îó²îͨ¸æ¡¿Polkit pkexecȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©

Ðû²¼Ê±¼ä 2022-01-26


0x00 Îó²î¸ÅÊö

CVE    ID

CVE-2021-4034

ʱ      ¼ä

2022-01-25

Àà      ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


Óû§½»»¥


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

Polkit£¨PolicyKit£©ÊÇÒ»¸öÓÃÓÚ¿ØÖÆÀàUnixϵͳÖÐϵͳ¹æÄ£È¨ÏÞµÄ×é¼þ£¬£¬£¬£¬ £¬£¬£¬ËüΪ·ÇÌØÈ¨Àú³ÌÓëÌØÈ¨Àú³ÌµÄͨѶÌṩÁËÒ»ÖÖÓÐ×éÖ¯µÄ·½·¨¡£¡£¡£ ¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö£¬£¬£¬£¬ £¬£¬£¬ËüÈÏÕæÐ­ÉÌÌØÈ¨Àú³ÌºÍ·ÇÌØÈ¨Àú³ÌÖ®¼äµÄ»¥¶¯£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔÁíÒ»¸öÓû§µÄÉí·ÝÖ´ÐÐÏÂÁ£¬£¬£¬ £¬£¬£¬ÊÇsudoµÄÌæ»»¼Æ»®¡£¡£¡£ ¡£

1ÔÂ25ÈÕ£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶ÁËÔÚ polkit µÄ pkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034 £¬£¬£¬£¬ £¬£¬£¬Ò²³ÆPwnKit)£¬£¬£¬£¬ £¬£¬£¬Ëü±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæµÄĬÈÏÉèÖÃÖС£¡£¡£ ¡£ÊÜÓ°Ïì°æ±¾µÄ pkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý¼ÆÊý£¬£¬£¬£¬ £¬£¬£¬×îÖÕʵÑ齫ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬£¬£¬£¬ £¬£¬£¬ÓÕʹ pkexec Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬ £¬£¬£¬´Ó¶øµ¼Ö½«ÍâµØÈ¨ÏÞÌáÉýΪroot¡£¡£¡£ ¡£

×Ô2009Äê5ÔµĵÚÒ»¸ö°æ±¾£¨Ìá½»c8c3d83£¬£¬£¬£¬ £¬£¬£¬"Ìí¼Ópkexec(1)ÏÂÁî"£©ÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÖÁÉÙ±£´æÁË12Ä꣬£¬£¬£¬ £¬£¬£¬²¢Ó°Ïìµ½ËùÓа汾µÄpkexec¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ´ËÎó²îÒ×ÓÚʹÓ㬣¬£¬£¬ £¬£¬£¬ÇÒÊÖÒÕϸ½ÚÒѾ­¹ûÕæ£¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚÒÑÓйûÕæ¿ÉÓõÄPoC/EXP¡£¡£¡£ ¡£

 

Ó°Ïì¹æÄ£

×Ô2009ÄêÒÔÀ´µÄËùÓÐ Polkit °æ±¾£¨±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæÖУ©¡£¡£¡£ ¡£

 

0x02 Çå¾²½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£ ¡£

²¹¶¡ÏÂÔØÁ´½Ó£º

https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683

×¢£º

1.UbuntuÒѾ­ÎªPolicyKitÍÆËÍÁ˸üУ¬£¬£¬£¬ £¬£¬£¬ÒÔ½â¾ö14.04ºÍ16.04 ESM°æ±¾ÒÔ¼°×î½üµÄ18.04¡¢20.04ºÍ21.04°æ±¾ÖеÄÎó²î¡£¡£¡£ ¡£

ÏÂÔØÁ´½Ó£º

https://ubuntu.com/security/notices/USN-5252-2

2.Red HatÒѾ­Îª Workstation ºÍ Enterprise ²úÆ·ÉϵÄpolkitÌṩÁËÇå¾²¸üС£¡£¡£ ¡£

ÏÂÔØÁ´½Ó£º

https://access.redhat.com/security/security-updates/#/security-advisories

3.ÈôÊÇϵͳûÓпÉÓõIJ¹¶¡£¡£¡£ ¡£¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔ´Ó pkexec ÖÐɾ³ý SUID λ×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬ £¬£¬£¬È磺chmod 0755 /usr/bin/pkexec


0x03 ²Î¿¼Á´½Ó

https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034

https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/

https://access.redhat.com/security/cve/cve-2021-4034

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-01-26

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ £¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬ £¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£ ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬ £¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬ £¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£ ¡£

¶àÄêÀ´£¬£¬£¬£¬ £¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬ £¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬ £¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£ ¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£ ¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬ £¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png