A race condition exists in the pkexec utility and polkitd daemon in PolicyKit (polkit) version 0.96. The vulnerability arises from the use of the effective user ID instead of the real user ID when executing setuid programs from pkexec. This allows a local attacker to exploit the race condition to gain elevated privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small local privilege-escalation exploit for CVE-2011-1485 affecting polkit/pkexec 0.96 on Linux. It contains only two files: a brief README and a single shell script, pkexec.sh, which embeds two C programs via here-docs, compiles them, and executes the exploit chain. Repository structure and purpose: - README.md: minimal description naming CVE-2011-1485. - pkexec.sh: the full exploit. It includes a long comment explaining the vulnerability mechanics in polkit/pkexec, then writes and compiles two helper programs. Exploit flow: 1. suid.c is generated and compiled to /tmp/suid. This helper sets UID/GID to 0 and runs /bin/sh -c with attacker-supplied arguments. 2. makesuid.c is generated and compiled. It forks: - Parent branch creates an inotify watch on its own /proc/<pid> path and then execs /usr/bin/X. - Child branch execs /usr/bin/pkexec with attacker-controlled arguments. 3. The shell script runs makesuid twice to execute privileged file operations through pkexec: - chown root:root /tmp/suid - chmod u+s /tmp/suid 4. The script then launches /tmp/suid -c /bin/sh to obtain a root shell. Main exploit capability: - Local privilege escalation to root by abusing a race condition/TOCTOU weakness in polkit/pkexec process ownership validation and parent-process handling. Notable implementation details: - The exploit is operational rather than a mere proof of concept because it automates compilation, privilege abuse, SUID creation, and root shell execution. - It is not a remote exploit and exposes no network service interaction; all activity is local to the host. - The script references vulnerable source-code paths and patch rationale in comments, but the active exploit logic is the shell script plus the generated C helpers.
This repository contains a single Metasploit module (modules/exploits/linux/local/pkexec.rb) that exploits a local privilege escalation vulnerability (CVE-2011-1485) in the PolicyKit pkexec utility on Linux systems. The exploit leverages a race condition to execute arbitrary commands as root. The module is written in Ruby and dynamically generates and compiles a C payload, which is then executed on the target system. The payload is customizable and can provide either a shell or Meterpreter session as root. The exploit requires local access to the target system and the ability to write to a directory such as /tmp. The module is operational and suitable for use in real-world penetration testing scenarios against vulnerable Linux distributions (notably older versions of RHEL and Ubuntu). The only fingerprintable endpoints are the /tmp directory (used for dropping the exploit binary) and the pkexec binary itself (the target of the exploit).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.