CVE•Published 2022-02-16•1 article on news•6 live references•NVD data

CVE-2021-3560

Vulnerability data via CVEDB (Shodan)

CISA KEVKnown exploited in the wild.
CISA action: Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.
CVSS v3.1
7.8
HIGH
EPSS percentile
98
Exploit Prediction Scoring System · top 2% of all CVEs
Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Timeline
Published 2022-02-16

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)

cipher387/osint_stuff_tool_collectionHTML
A collection of several hundred online tools for OSINT
★ 8,911·updated 4mo ago
Mr-xn/Penetration_Testing_POCHTML
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypas…
★ 7,505·updated 1d ago
0xsyr0/OSCPPowerShell
OSCP Cheat Sheet
★ 3,861·updated 3w ago
taielab/awesome-hacking-listsunknown
A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and enhance your hacking toolkit!
★ 1,391·updated 10mo ago
rng70/TryHackMe-Roadmapunknown
a list of 350+ Free TryHackMe rooms to start learning cybersecurity with THM
★ 1,305·updated 11mo ago
Ignitetechnologies/Linux-Privilege-Escalationunknown
This cheatsheet is aimed at the OSCP aspirants to help them understand the various methods of Escalating Privilege on Linux based Machines and CTFs with examples.
★ 994·updated 6mo ago
Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
★ 619·updated 5d ago
uttambodara/TryHackMeRoadmapunknown
A list of 350+ free TryHackMe rooms💻 to kick off your cybersecurity learning, organized by topics for easy exploration and practical skill-building !💀💥
★ 581·updated 1mo ago