¡¾Îó²îͨ¸æ¡¿Polkit pkexecȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©

Ðû²¼Ê±¼ä 2022-01-26


0x00 Îó²î¸ÅÊö

CVE    ID

CVE-2021-4034

ʱ      ¼ä

2022-01-25

Àà      ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


Óû§½»»¥


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

Polkit£¨PolicyKit£©ÊÇÒ»¸öÓÃÓÚ¿ØÖÆÀàUnixϵͳÖÐϵͳ¹æÄ£È¨ÏÞµÄ×é¼þ£¬£¬£¬£¬£¬ËüΪ·ÇÌØÈ¨Àú³ÌÓëÌØÈ¨Àú³ÌµÄͨѶÌṩÁËÒ»ÖÖÓÐ×éÖ¯µÄ·½·¨¡£¡£¡£¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö£¬£¬£¬£¬£¬ËüÈÏÕæÐ­ÉÌÌØÈ¨Àú³ÌºÍ·ÇÌØÈ¨Àú³ÌÖ®¼äµÄ»¥¶¯£¬£¬£¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔÁíÒ»¸öÓû§µÄÉí·ÝÖ´ÐÐÏÂÁ£¬£¬£¬£¬ÊÇsudoµÄÌæ»»¼Æ»®¡£¡£¡£¡£

1ÔÂ25ÈÕ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶ÁËÔÚ polkit µÄ pkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034 £¬£¬£¬£¬£¬Ò²³ÆPwnKit)£¬£¬£¬£¬£¬Ëü±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæµÄĬÈÏÉèÖÃÖС£¡£¡£¡£ÊÜÓ°Ïì°æ±¾µÄ pkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý¼ÆÊý£¬£¬£¬£¬£¬×îÖÕʵÑ齫ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬ÓÕʹ pkexec Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬´Ó¶øµ¼Ö½«ÍâµØÈ¨ÏÞÌáÉýΪroot¡£¡£¡£¡£

×Ô2009Äê5ÔµĵÚÒ»¸ö°æ±¾£¨Ìá½»c8c3d83£¬£¬£¬£¬£¬"Ìí¼Ópkexec(1)ÏÂÁî"£©ÒÔÀ´£¬£¬£¬£¬£¬¸ÃÎó²îÖÁÉÙ±£´æÁË12Ä꣬£¬£¬£¬£¬²¢Ó°Ïìµ½ËùÓа汾µÄpkexec¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÓÉÓÚ´ËÎó²îÒ×ÓÚʹÓ㬣¬£¬£¬£¬ÇÒÊÖÒÕϸ½ÚÒѾ­¹ûÕæ£¬£¬£¬£¬£¬ÏÖÔÚÒÑÓйûÕæ¿ÉÓõÄPoC/EXP¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

×Ô2009ÄêÒÔÀ´µÄËùÓÐ Polkit °æ±¾£¨±£´æÓÚËùÓÐÖ÷Á÷µÄ Linux ¿¯ÐаæÖУ©¡£¡£¡£¡£

 

0x02 Çå¾²½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£

²¹¶¡ÏÂÔØÁ´½Ó£º

https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683

×¢£º

1.UbuntuÒѾ­ÎªPolicyKitÍÆËÍÁ˸üУ¬£¬£¬£¬£¬ÒÔ½â¾ö14.04ºÍ16.04 ESM°æ±¾ÒÔ¼°×î½üµÄ18.04¡¢20.04ºÍ21.04°æ±¾ÖеÄÎó²î¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://ubuntu.com/security/notices/USN-5252-2

2.Red HatÒѾ­Îª Workstation ºÍ Enterprise ²úÆ·ÉϵÄpolkitÌṩÁËÇå¾²¸üС£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://access.redhat.com/security/security-updates/#/security-advisories

3.ÈôÊÇϵͳûÓпÉÓõIJ¹¶¡£¡£¡£¡£¬£¬£¬£¬£¬¿ÉÒÔ´Ó pkexec ÖÐɾ³ý SUID λ×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬£¬È磺chmod 0755 /usr/bin/pkexec


0x03 ²Î¿¼Á´½Ó

https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034

https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/

https://access.redhat.com/security/cve/cve-2021-4034

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-01-26

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¿­·¢k8¼ò½é

¿­·¢k8¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬¿­·¢k8ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£

 

¹ØÓÚ¿­·¢k8

¿­·¢k8Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png