¡¾Îó²îͨ¸æ¡¿Polkit pkexecȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©

Ðû²¼Ê±¼ä 2022-01-26


0x00 Îó²î¸ÅÊö

CVE    ID

CVE-2021-4034

ʱ      ¼ä

2022-01-25

Àà      ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


Óû§½»»¥


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

Polkit£¨PolicyKit£©ÊÇÒ»¸öÓÃÓÚ¿ØÖÆÀàUnixϵͳÖÐϵͳ¹æÄ£È¨ÏÞµÄ×é¼þ£¬£¬£¬ËüΪ·ÇÌØÈ¨Àú³ÌÓëÌØÈ¨Àú³ÌµÄͨѶÌṩÁËÒ»ÖÖÓÐ×éÖ¯µÄ·½·¨ ¡£¡£¡£¡£¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö£¬£¬£¬ËüÈÏÕæÐ­ÉÌÌØÈ¨Àú³ÌºÍ·ÇÌØÈ¨Àú³ÌÖ®¼äµÄ»¥¶¯£¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔÁíÒ»¸öÓû§µÄÉí·ÝÖ´ÐÐÏÂÁ£¬£¬ÊÇsudoµÄÌæ»»¼Æ»® ¡£¡£¡£¡£¡£

1ÔÂ25ÈÕ£¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶ÁËÔÚ polkit µÄ pkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034 £¬£¬£¬Ò²³ÆPwnKit)£¬£¬£¬Ëü±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæµÄĬÈÏÉèÖÃÖÐ ¡£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾µÄ pkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý¼ÆÊý£¬£¬£¬×îÖÕʵÑ齫ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬£¬£¬ÓÕʹ pkexec Ö´ÐÐí§Òâ´úÂ룬£¬£¬´Ó¶øµ¼Ö½«ÍâµØÈ¨ÏÞÌáÉýΪroot ¡£¡£¡£¡£¡£

×Ô2009Äê5ÔµĵÚÒ»¸ö°æ±¾£¨Ìá½»c8c3d83£¬£¬£¬"Ìí¼Ópkexec(1)ÏÂÁî"£©ÒÔÀ´£¬£¬£¬¸ÃÎó²îÖÁÉÙ±£´æÁË12Ä꣬£¬£¬²¢Ó°Ïìµ½ËùÓа汾µÄpkexec ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ÓÉÓÚ´ËÎó²îÒ×ÓÚʹÓ㬣¬£¬ÇÒÊÖÒÕϸ½ÚÒѾ­¹ûÕæ£¬£¬£¬ÏÖÔÚÒÑÓйûÕæ¿ÉÓõÄPoC/EXP ¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

×Ô2009ÄêÒÔÀ´µÄËùÓÐ Polkit °æ±¾£¨±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæÖУ© ¡£¡£¡£¡£¡£

 

0x02 Çå¾²½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üР¡£¡£¡£¡£¡£

²¹¶¡ÏÂÔØÁ´½Ó£º

https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683

×¢£º

1.UbuntuÒѾ­ÎªPolicyKitÍÆËÍÁ˸üУ¬£¬£¬ÒÔ½â¾ö14.04ºÍ16.04 ESM°æ±¾ÒÔ¼°×î½üµÄ18.04¡¢20.04ºÍ21.04°æ±¾ÖеÄÎó²î ¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://ubuntu.com/security/notices/USN-5252-2

2.Red HatÒѾ­Îª Workstation ºÍ Enterprise ²úÆ·ÉϵÄpolkitÌṩÁËÇå¾²¸üР¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://access.redhat.com/security/security-updates/#/security-advisories

3.ÈôÊÇϵͳûÓпÉÓõIJ¹¶¡£¬£¬£¬¿ÉÒÔ´Ó pkexec ÖÐɾ³ý SUID λ×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬È磺chmod 0755 /usr/bin/pkexec


0x03 ²Î¿¼Á´½Ó

https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034

https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/

https://access.redhat.com/security/cve/cve-2021-4034

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-01-26

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

ÄϹ¬NGÓéÀÖ¼ò½é

ÄϹ¬NGÓéÀÖ¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ ¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬ÄϹ¬NGÓéÀÖÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢ ¡£¡£¡£¡£¡£

 

¹ØÓÚÄϹ¬NGÓéÀÖ

ÄϹ¬NGÓéÀÖÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png