CVE-2021-3560 is a local privilege-escalation vulnerability in Polkit's polkit_system_bus_name_get_creds_sync() credential-resolution path. A race condition combined with improper handling of D-Bus credential-lookup errors could leave UID data uninitialized while authorization processing continued. Under exploitable conditions, Polkit could treat the requester as UID 0 and authorize a privileged D-Bus operation without valid credential verification.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
17 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
Repository contains a simple two-file local privilege-escalation proof-of-concept for CVE-2021-3560. The README explains the underlying polkit race condition and how to derive a working timing window using dbus-send against AccountsService. The sole code file, exploit_dbus.py, is a standalone Python script that automates the attack in two phases: first it repeatedly issues a system D-Bus CreateUser request to org.freedesktop.Accounts with int32:1 to create an administrative user, then sleeps for a randomized interval within a configured timing range and terminates dbus-send to trigger the authorization race. After confirming the user exists with id, it retrieves the UID, generates a SHA-512 password hash with Python's crypt module, and repeatedly invokes org.freedesktop.Accounts.User.SetPassword on /org/freedesktop/Accounts/User<uid>, again terminating the request mid-flight to exploit the same flaw. It verifies success by attempting su to the new account. The exploit is operational but basic: credentials and timing range are hardcoded, success depends on local timing, and there is no modular payloading or framework integration. Primary capability is creation of a root-equivalent local admin account on vulnerable Linux systems.
Repository contains a README and a single Bash exploit script. The script is a local privilege-escalation exploit for CVE-2021-3560 in polkit/accounts-daemon on Linux. It repeatedly measures the response time of a system D-Bus CreateUser request, derives a kill window, and races dbus-send calls to org.freedesktop.Accounts.CreateUser and org.freedesktop.Accounts.User.SetPassword by launching them in the background and terminating them at a calculated moment. The exploit hardcodes username 'user', password 'pass', and stores a payload in /var/tmp. After the account is created and its password set, it uses su to switch into that account, attempts sudo commands, copies /bin/bash to /var/tmp/bash, sets the SUID bit, removes the created user with userdel, and launches /var/tmp/bash -ip for a root shell. The repository is small, purpose-built, and operational rather than a framework module; it contains an actual exploit with a basic hardcoded payload, not just detection logic.
This repository is a small, self-contained Bash proof-of-concept for CVE-2021-3560, a local privilege escalation vulnerability in polkit. It contains two files: a README describing the bug, prerequisites, and usage, and a single executable script, poc.sh, which performs the exploit workflow. The exploit is local-only and does not target remote network services. Its core capability is to win a timing race in polkit while interacting with AccountsService over the system D-Bus. The script first optionally checks whether the host appears vulnerable by identifying the Linux distribution from /etc/os-release, verifying that accountsservice and gnome-control-center are installed via dpkg or rpm, and checking polkit package versions that match the vulnerable ranges hardcoded by the author. If exploitation proceeds, the script measures how long a dbus-send CreateUser request takes, derives a sleep interval from that timing, and then repeatedly launches and kills CreateUser requests against org.freedesktop.Accounts to trigger the race. Once the user is created, it generates a password hash with openssl passwd -5 and repeatedly races a SetPassword request against the per-user AccountsService object path to assign the attacker-controlled password. The intended end state is a new local account with known credentials that can then be used to run sudo bash and obtain a root shell. Notable fingerprintable targets are not IPs or URLs but local system interfaces and resources: /etc/os-release, package manager queries, the D-Bus destination org.freedesktop.Accounts, object paths /org/freedesktop/Accounts and /org/freedesktop/Accounts/User<uid>, and the methods org.freedesktop.Accounts.CreateUser and org.freedesktop.Accounts.User.SetPassword. The script defaults to username 'secnigma' and password 'secnigmaftw', but both can be customized via command-line arguments. Overall, this is a real exploit PoC rather than a detector. It is operational but basic: it automates the race and account creation steps with hardcoded logic and repeated attempts, without framework integration or advanced payload customization.
This repository is a compact C-based local privilege escalation exploit for CVE-2021-3560 in PolicyKit/polkit on Linux. It is not part of a larger exploit framework. The repository contains 6 files: a Makefile, README, headers, and two C source files implementing the exploit logic. The main entry point is exploit.c, while agent.c implements a malicious PolicyKit authentication agent over system D-Bus. Structure and purpose: - exploit.c: orchestrates exploitation. It writes a malicious systemd unit file under /tmp, forks into multiple processes, starts fake authentication agents, and concurrently issues privileged D-Bus calls to systemd: EnableUnitFiles, StartUnit, and Reload. - agent.c: registers a fake org.freedesktop.PolicyKit1.AuthenticationAgent object on the system bus and handles BeginAuthentication requests. When polkit asks for authorization, the code immediately responds via AuthenticationAgentResponse2 using the supplied cookie, then kills the process to exploit the race condition associated with CVE-2021-3560. - agent.h: minimal header for the authentication agent thread entry point. - Makefile: builds a single binary named exploit using gio, dbus-1, and dbus-glib. - README.md: documents usage and demonstrates successful root shell acquisition. Main exploit capability: The exploit performs local privilege escalation by abusing vulnerable polkit authorization handling on the system bus. It registers one or more fake authentication agents and races privileged systemd management operations so polkit incorrectly authorizes them. Once authorized, the exploit enables and starts a crafted service that runs as root. Payload behavior: The payload is hardcoded in the generated unit file. The service executes /bin/bash -c 'cp /bin/bash /usr/local/bin/pwned; chmod +s /usr/local/bin/pwned', creating a SUID-root bash copy. The parent process then checks for /usr/local/bin/pwned and runs '/usr/local/bin/pwned -p' to obtain a root shell. Notable implementation details: - Uses GIO/GDBus on the system bus rather than raw sockets or HTTP. - Registers the malicious agent at /org/freedesktop/PolicyKit1/AuthenticationAgent. - Targets three privileged systemd actions in parallel to improve race reliability: manage-unit-files, manage-units, and reload-daemon. - The exploit is operational rather than just a PoC because it includes a complete privilege-escalation payload and shell-spawning logic, though the payload is hardcoded rather than user-customizable. There are no external network callbacks, C2 endpoints, or remote targets. All observable endpoints are local D-Bus service/interface/object names and filesystem paths used to create and launch the privileged payload.
This repository contains a proof-of-concept exploit for CVE-2021-3560, a privilege escalation vulnerability in polkit on Linux. The main file, CVE-2021-3560.py, is a Python script that leverages DBus method calls to create a new privileged user ('pentester') and set its password to a known value ('Expl01ted'). The script repeatedly attempts to create the user and set the password using DBus commands, exploiting a race condition in polkit's handling of authentication. Once the user is created and the password is set, the script spawns a shell as the new privileged user, effectively granting root access to the attacker. The exploit is local and requires the attacker to have access to a shell on the target system. The repository also includes a README.md with a brief description and usage instructions. The exploit targets Linux systems running vulnerable versions of polkit prior to the patch for CVE-2021-3560.
This repository contains a Bash proof-of-concept exploit for CVE-2021-3560, a local privilege escalation vulnerability in polkit (versions >0.105 and <0.120) on Linux. The exploit is implemented in a single Bash script ('exploit3560.sh') that attempts to create a new privileged user ('pwned') by racing the polkit authorization check using dbus-send. The script checks for the presence of required binaries (dbus-send, pkexec), verifies the polkit version, and then repeatedly attempts to create the user and set its password using DBus method calls. If successful, the attacker can escalate privileges by switching to the new user and using sudo. The README provides background, usage instructions, and references. The exploit is operational and automates the race condition, but does not provide a customizable payload beyond the creation of a privileged user.
This repository contains a Python exploit for CVE-2021-3650, a privilege escalation vulnerability in polkit (version 0.105-26) on Linux. The main file, polkit.py, checks for a vulnerable polkit version and requires the user to be connected via SSH to avoid authentication prompts. The exploit works by rapidly sending D-Bus method calls to the org.freedesktop.Accounts service to create a new user and set its password, exploiting a race condition. If successful, this results in a new user account with elevated privileges. The repository consists of a README and the exploit script, with the latter being the main entry point and containing all exploit logic. No network endpoints are targeted; the attack vector is local, requiring shell access to the vulnerable system.
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2021-3560, a local privilege escalation vulnerability in polkit on Linux. The exploit works by abusing a race condition in the D-Bus authentication process, allowing an unprivileged local user to create a new user account with root privileges. The module automates the process of creating the user, setting a known password, and then using this account to execute a user-supplied payload as root. After exploitation, the module attempts to remove the created user to clean up. The exploit requires local access to the target system and is operational, providing reliable privilege escalation on vulnerable systems. The main endpoints involved are the D-Bus service 'org.freedesktop.Accounts' and the writable directory '/tmp' for payload operations. The code is structured as a typical Metasploit local exploit module, with options for username, password, timeout, and number of iterations to handle the race condition.
This repository contains a Bash script (exploit.sh) that exploits CVE-2021-3560, a privilege escalation vulnerability in polkit on Linux systems. The exploit works by racing the dbus-send command to create a new user with root privileges and then set a known password for that user. The script attempts the race condition multiple times for reliability. The README.md provides usage instructions, expected results, and references. The main exploit file is exploit.sh, which is self-contained and operational, requiring only local shell access on a vulnerable system. The script interacts with the D-Bus system service at /org/freedesktop/Accounts to manipulate user accounts. No network endpoints are involved; the attack vector is local privilege escalation.
This repository contains a Metasploit module (CVE-2021-3560.rb) that exploits a local privilege escalation vulnerability in polkit (CVE-2021-3560) on Linux systems. The exploit leverages a race condition in the polkit D-Bus authentication process, allowing an unprivileged local attacker to create a new user with root privileges by manipulating D-Bus method calls and process timing. The module then uses this new user to execute a payload (such as a shell or meterpreter session) as root. After exploitation, the module attempts to remove the created user. The exploit requires local shell access and the presence of the 'dbus-send' utility. The repository also includes a README.md file describing the vulnerability and exploit at a high level. The main exploit logic is implemented in Ruby as a Metasploit module, making it easy to customize payloads and integrate into offensive security workflows.
This repository provides a working exploit for CVE-2021-3560, a privilege escalation vulnerability in polkit (PolicyKit) affecting Linux systems with polkit versions prior to 0.118. The exploit leverages a race condition in polkit's D-Bus authentication mechanism, allowing a local attacker to create a new user with sudo privileges and set its password without proper authentication. The repository contains three files: a detailed README.md with step-by-step manual exploitation instructions, a lessson.md file explaining the vulnerability and mitigation strategies, and a Bash script (poc.sh) that automates the exploitation process. The script checks for the presence of required packages and the vulnerable polkit version, then attempts the timing-based attack by sending D-Bus messages to the org.freedesktop.Accounts service. The exploit is operational, providing a reliable method to escalate privileges on unpatched systems. No network endpoints are targeted; the attack is purely local, requiring shell access to the vulnerable machine.
This repository contains a C-based local privilege escalation exploit for CVE-2021-3560, a vulnerability in polkit on Linux. The exploit leverages a race condition in polkit's D-Bus authentication, allowing an unprivileged user to create a new privileged (administrator) user and set its password to empty by abusing the accountsservice D-Bus API. The repository consists of three files: a .gitignore, a detailed README.md explaining the vulnerability and usage, and the main exploit code in exploit.c. The exploit works by rapidly sending D-Bus method calls to create a user and set its password, then killing the process at a precise moment to bypass authentication checks. The exploit is operational and provides a shell as the new privileged user, enabling full root access. The main fingerprintable endpoints are the D-Bus service 'org.freedesktop.Accounts', the file '/etc/shadow', and the use of '/usr/bin/su' to escalate to root.
This repository contains a Python exploit for CVE-2021-3560, a privilege escalation vulnerability in polkit on Linux systems. The main file, CVE-2021-3560.py, automates the exploitation process by repeatedly sending crafted DBus messages to the org.freedesktop.Accounts service, exploiting a race condition to create a new user ('ahmed') without proper authentication. It then sets a password for this user and attempts to escalate privileges to root by spawning a root shell. The exploit is operational and provides a working privilege escalation path on vulnerable systems. The repository also includes a README.md with usage instructions, background information, and demonstration GIFs. The attack vector is local, requiring shell access to the target system. The exploit interacts with DBus endpoints such as /org/freedesktop/Accounts and org.freedesktop.Accounts.
This repository contains a Bash proof-of-concept exploit for CVE-2021-3560, a privilege escalation vulnerability in polkit on Linux systems. The exploit automates the attack described by Kevin Backhouse, leveraging a timing issue in polkit's DBus authentication to create a new user with root privileges. The main script, 'poc.sh', checks for the presence of required packages ('accountsservice', 'gnome-control-center'), verifies the polkit version, and then attempts the exploit by sending carefully timed DBus messages to create a new user and set its password. The script allows customization of username, password, and timing parameters, and can force exploitation even if checks fail. The README provides detailed usage instructions and background on the vulnerability. The exploit is operational and, if successful, grants the attacker a root shell via the newly created user. The attack vector is local, requiring shell access to the target system. Key fingerprintable endpoints include the use of '/etc/os-release' for OS detection and DBus object paths for user management.
This repository contains a Python exploit for CVE-2021-3560, a local privilege escalation vulnerability in Polkit (versions 0.0 to 0.118) on Linux systems. The exploit script (exploit-CVE-2021-3560.py) leverages a race condition in Polkit's D-Bus authentication to create a new local user with sudo privileges and a specified password, effectively granting root access to an unprivileged local attacker. The script checks for required dependencies, interacts with the system's /etc/passwd and /etc/shadow files to confirm user creation and password setting, and uses the 'dbus-send' command to interact with the vulnerable D-Bus interface. The repository also includes a Dockerfile (for building a test environment, though not fully functional) and a README.md with detailed usage instructions, requirements, and background on the vulnerability. The exploit is operational, providing a working privilege escalation method on affected systems.
This repository contains a Bash script exploit ('polkadots') targeting CVE-2021-3560, a local privilege escalation vulnerability in polkit on several Linux distributions (RHEL 8, Fedora 21, Debian Bullseye, Ubuntu 20.04). The exploit works by racing D-Bus method calls to create a new privileged user account and set its password hash, allowing the attacker to escalate privileges to root. The script is configurable via command-line arguments for the account name, full name, password hash, and number of iterations for the race. The main code file is 'polkadots', which is a standalone Bash script. The repository also includes a README with usage instructions and a LICENSE file. The exploit does not require network access and operates entirely locally, targeting the D-Bus interface of the accounts service.
This repository is an operational exploit for CVE-2021-3560, a privilege escalation vulnerability in PolicyKit (polkit) on Linux. The exploit is implemented in Go and consists of two main code files: 'exploit.go' and 'agent.go'. The exploit works by registering a fake PolicyKit authentication agent via D-Bus, then using systemd's D-Bus interface to enable and start a malicious systemd service ('pwnkit.service'). This service copies /bin/bash to /usr/local/bin/pwned and sets the setuid bit, creating a root shell. The exploit attempts to trigger the vulnerability by racing the PolicyKit authentication process, and if successful, provides the attacker with a root shell. The repository includes a sample systemd unit file ('pwnkit.service') as the payload. The attack vector is local, requiring the attacker to execute the exploit on a vulnerable Linux system. The exploit targets PolicyKit (polkit) on Linux systems vulnerable to CVE-2021-3560. No network endpoints are involved, but several D-Bus and file system endpoints are fingerprintable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege-escalation vulnerability in polkit involving polkit_system_bus_name_get_creds_sync(), affecting the installed Rocky Linux 8 packages.
A local privilege escalation vulnerability in PolicyKit caused by improper handling of errors during D-Bus credential lookup for a bus name, allowing authentication to proceed with uninitialized UID data that could be interpreted as root under a race condition.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.