cve/2021/CVE-2021-3560.md
2024-08-30 20:52:42 +00:00

6.3 KiB

CVE-2021-3560

Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

POC

Reference

Github