News | HiddenRefer

Navigation

  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Subscribe
News | HiddenRefer

The Best Curated Freebies in One Place

0
0
0
0
News | HiddenRefer
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
  • Security

12-Year-Old Polkit Flaw Lets Unprivileged Linux Users Gain Root Access

  • January 26, 2022
  • hiddenrefer
12-Year-Old Polkit Flaw Lets Unprivileged Linux Users Gain Root Access
Total
0
Shares
0
0
0
Advertisements

A 12-year-old security vulnerability has been disclosed in a system utility called Polkit that grants attackers root privileges on Linux systems, even as a proof-of-concept (PoC) exploit has emerged in the wild merely hours after technical details of the bug became public.

Dubbed “PwnKit” by cybersecurity firm Qualys, the weakness impacts a component in polkit called pkexec, a program that’s installed by default on every major Linux distribution such as Ubunti, Debian, Fedora, and CentOS.

Polkit (formerly called PolicyKit) is a toolkit for controlling system-wide privileges in Unix-like operating systems, and provides a mechanism for non-privileged processes to communicate with privileged processes.

Automatic GitHub Backups

“This vulnerability allows any unprivileged user to gain full root privileges on a vulnerable host by exploiting this vulnerability in its default configuration,” Bharat Jogi, director of vulnerability and threat research at Qualys, said, adding it “has been hiding in plain sight for 12+ years and affects all versions of pkexec since its first version in May 2009.”

The flaw, which concerns a case of memory corruption and has been assigned the identifier CVE-2021-4034, was reported to Linux vendors on November 18, 2021, following which patches have been issued by Red Hat and Ubuntu.

pkexec, analogous to the sudo command, allows an authorized user to execute commands as another user, doubling as an alternative to sudo. If no username is specified, the command to be executed will be run as the administrative super user, root.

PwnKit stems from an out-of-bounds write that enables the reintroduction of “unsecure” environment variables into pkexec’s environment. While this vulnerability is not remotely exploitable, an attacker that has already established a foothold on a system via another means can weaponize the flaw to achieve full root privileges.

Prevent Data Breaches

Complicating matters is the emergence of a PoC in the wild, which CERT/CC vulnerability analyst Will Dormann called “simple and universal,” making it absolutely vital that the patches are applied as soon as possible to contain potential threats.

The development marks the second security flaw uncovered in Polkit in as many years. In June 2021, GitHub security researcher Kevin Backhouse revealed details of a seven-year-old privilege escalation vulnerability (CVE-2021-3560) that could be abused to escalate permissions to the root user.

On top of that, the disclosure also arrives close on the heels of a security flaw affecting the Linux kernel (CVE-2022-0185) that could be exploited by an attacker with access to a system as an unprivileged user to escalate those rights to root and break out of containers in Kubernetes setups.



Total
0
Shares
Share 0
Tweet 0
Pin it 0
hiddenrefer

Previous Article
Man goes on anti-mask tirade against Glendale Unified students
  • Crime News

Man goes on anti-mask tirade against Glendale Unified students

  • January 26, 2022
  • hiddenrefer
View & Download
Next Article
California bill would ban single-use cigarette filters
  • Crime News

California bill would ban single-use cigarette filters

  • January 26, 2022
  • hiddenrefer
View & Download
You May Also Like
UpdateAgent Returns with New macOS Malware Dropper Written in Swift
View & Download
  • Security

UpdateAgent Returns with New macOS Malware Dropper Written in Swift

  • hiddenrefer
  • May 17, 2022
Securing Your Data in the Cloud
View & Download
  • Security

Are You Investing in Securing Your Data in the Cloud?

  • hiddenrefer
  • May 17, 2022
U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware
View & Download
  • Security

U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware

  • hiddenrefer
  • May 17, 2022
srv botnet
View & Download
  • Security

New Sysrv Botnet Variant Hijacking Windows and Linux with Crypto Miners

  • hiddenrefer
  • May 17, 2022
Androids with Password Stealer
View & Download
  • Security

Over 200 Apps on Play Store Caught Spying on Android Users Using Facestealer

  • hiddenrefer
  • May 17, 2022
Making a successful transition to a hybrid work schedule
View & Download
  • Security

Making a successful transition to a hybrid work schedule

  • hiddenrefer
  • May 17, 2022
Zyxel Firewalls RCE Vulnerability
View & Download
  • Security

Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE Vulnerability

  • hiddenrefer
  • May 17, 2022
Malware
View & Download
  • Security

Researchers Find Potential Way to Run Malware on iPhone Even When it’s OFF

  • hiddenrefer
  • May 16, 2022
  • Los Angeles doctor accused of issuing fake COVID vaccine cards
    Los Angeles doctor accused of issuing fake COVID vaccine cards
    • May 18, 2022
  • Twisted diary of alleged Buffalo shooter Payton Gendron reveals his online radicalization
    Twisted diary of alleged Buffalo shooter Payton Gendron reveals his online radicalization
    • May 17, 2022
  • California church shooting suspect David Chou charged with murder
    California church shooting suspect David Chou charged with murder
    • May 17, 2022
  • Brush fire contained near Griffith Observatory, person detained
    Brush fire contained near Griffith Observatory, person detained
    • May 17, 2022
  • Glendale apologizes for sending alert to Los Angeles County
    Glendale apologizes for sending alert to Los Angeles County
    • May 17, 2022

Featured Categories

Cloud Security
243 Posts
View Posts
Crime News
3153 Posts
View Posts
Cybersecurity
202 Posts
View Posts
Data Breaches
70 Posts
View Posts
Drug Raids
122 Posts
View Posts
Privacy
93 Posts
View Posts
Security
979 Posts
View Posts
about
Navigation
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Featured
  • Los Angeles doctor accused of issuing fake COVID vaccine cards
    Los Angeles doctor accused of issuing fake COVID vaccine cards
    • May 18, 2022
  • Twisted diary of alleged Buffalo shooter Payton Gendron reveals his online radicalization
    Twisted diary of alleged Buffalo shooter Payton Gendron reveals his online radicalization
    • May 17, 2022
  • California church shooting suspect David Chou charged with murder
    California church shooting suspect David Chou charged with murder
    • May 17, 2022
  • Brush fire contained near Griffith Observatory, person detained
    Brush fire contained near Griffith Observatory, person detained
    • May 17, 2022
  • Glendale apologizes for sending alert to Los Angeles County
    Glendale apologizes for sending alert to Los Angeles County
    • May 17, 2022
News | HiddenRefer
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Input your search keywords and press Enter.