¡¾Îó²îͨ¸æ¡¿Polkit pkexecȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©
Ðû²¼Ê±¼ä 2022-01-260x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-4034 | ʱ ¼ä | 2022-01-25 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | Óû§½»»¥ | ||
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
Polkit£¨PolicyKit£©ÊÇÒ»¸öÓÃÓÚ¿ØÖÆÀàUnixϵͳÖÐϵͳ¹æÄ£È¨ÏÞµÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬ËüΪ·ÇÌØÈ¨Àú³ÌÓëÌØÈ¨Àú³ÌµÄͨѶÌṩÁËÒ»ÖÖÓÐ×éÖ¯µÄ·½·¨¡£¡£¡£¡£¡£¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬ËüÈÏÕæÐÉÌÌØÈ¨Àú³ÌºÍ·ÇÌØÈ¨Àú³ÌÖ®¼äµÄ»¥¶¯£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔÁíÒ»¸öÓû§µÄÉí·ÝÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬£¬ÊÇsudoµÄÌæ»»¼Æ»®¡£¡£¡£¡£¡£¡£
1ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶ÁËÔÚ polkit µÄ pkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034 £¬£¬£¬£¬£¬£¬£¬Ò²³ÆPwnKit)£¬£¬£¬£¬£¬£¬£¬Ëü±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæµÄĬÈÏÉèÖÃÖС£¡£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾µÄ pkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý¼ÆÊý£¬£¬£¬£¬£¬£¬£¬×îÖÕʵÑ齫ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬ÓÕʹ pkexec Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö½«ÍâµØÈ¨ÏÞÌáÉýΪroot¡£¡£¡£¡£¡£¡£
×Ô2009Äê5ÔµĵÚÒ»¸ö°æ±¾£¨Ìá½»c8c3d83£¬£¬£¬£¬£¬£¬£¬"Ìí¼Ópkexec(1)ÏÂÁî"£©ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÖÁÉÙ±£´æÁË12Ä꣬£¬£¬£¬£¬£¬£¬²¢Ó°Ïìµ½ËùÓа汾µÄpkexec¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´ËÎó²îÒ×ÓÚʹÓ㬣¬£¬£¬£¬£¬£¬ÇÒÊÖÒÕϸ½ÚÒѾ¹ûÕæ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑÓйûÕæ¿ÉÓõÄPoC/EXP¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
×Ô2009ÄêÒÔÀ´µÄËùÓÐ Polkit °æ±¾£¨±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæÖУ©¡£¡£¡£¡£¡£¡£
0x02 Çå¾²½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£¡£
²¹¶¡ÏÂÔØÁ´½Ó£º
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
×¢£º
1.UbuntuÒѾΪPolicyKitÍÆËÍÁ˸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ½â¾ö14.04ºÍ16.04 ESM°æ±¾ÒÔ¼°×î½üµÄ18.04¡¢20.04ºÍ21.04°æ±¾ÖеÄÎó²î¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://ubuntu.com/security/notices/USN-5252-2
2.Red HatÒѾΪ Workstation ºÍ Enterprise ²úÆ·ÉϵÄpolkitÌṩÁËÇå¾²¸üС£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://access.redhat.com/security/security-updates/#/security-advisories
3.ÈôÊÇϵͳûÓпÉÓõIJ¹¶¡£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ´Ó pkexec ÖÐɾ³ý SUID λ×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬£¬£¬£¬È磺chmod 0755 /usr/bin/pkexec
0x03 ²Î¿¼Á´½Ó
https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034
https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/
https://access.redhat.com/security/cve/cve-2021-4034
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-01-26 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£
¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º