{"id":399829,"date":"2022-01-26T19:08:41","date_gmt":"2022-01-26T16:08:41","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/12-year-old-linux-vulnerability-grants-root-access\/"},"modified":"2022-01-26T19:08:41","modified_gmt":"2022-01-26T16:08:41","slug":"12-year-old-linux-vulnerability-grants-root-access","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/12-year-old-linux-vulnerability-grants-root-access\/","title":{"rendered":"#12-Year-Old Linux Vulnerability Grants Root Access"},"content":{"rendered":"<p><strong>&#8220;#12-Year-Old Linux Vulnerability Grants Root Access&#8221;<\/strong><\/p>\n<div id=\"post-782149\">\n<div class=\"entry-content e-content\">\n<figure style=\"width: 1200px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage size-full wp-image-778840\" data-pagespeed-lazy-srcset=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2019\/06\/Linux-laptop-showing-a-bash-prompt.jpg?width=398&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 400w, https:\/\/www.howtogeek.com\/wp-content\/uploads\/2019\/06\/Linux-laptop-showing-a-bash-prompt.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 1200w\" sizes=\"auto, 400w, 1200w\" data-pagespeed-lazy-src=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2019\/06\/Linux-laptop-showing-a-bash-prompt.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"Linux laptop showing a bash prompt\" width=\"1200\" height=\"675\" src=\"\/pagespeed_static\/1.JiBnMqyl6S.gif\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-vector\/linux-interface-screen-notebook-world-map-321627716\">fatmawati achmad zaenuri\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p>Sometimes, it can take a long time before a vulnerability is exploited. In the case of this Polkit (fka PolicyKit) issue, we\u2019re talking about a 12-year-old bug that\u2019s just been discovered and shown off in a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/vimeo.com\/669715589?embedded=true&amp;source=video_title&amp;owner=42884007\">proof of concept<\/a>.<\/p>\n<p>According to researchers at <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2022\/01\/25\/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034\">Qualys<\/a>, this Polkit vulnerability is in the default configuration of all major Linux distributions. It can be used to gain full root access to a system, which can open up a whole new world of problems.<\/p>\n<p>\u201cThe Qualys Research Team has discovered a memory corruption vulnerability in polkit\u2019s pkexec, a SUID-root program that is installed by default on every major Linux distribution. This easily exploited vulnerability allows any unprivileged user to gain full root privileges on a vulnerable host by exploiting this vulnerability in its default configuration,\u201d said\u00a0Bharat Jogi, Director, Vulnerability and Threat Research, Qualys.<\/p>\n<p>The bug is called\u00a0CVE-2021-4034 or\u00a0PwnKit, and it\u2019s definitely something you want to watch out for if you\u2019re a Linux user. The issue isn\u2019t part of the Linux kernel itself, but part of the\u00a0Polkit software that\u2019s installed on almost every major distro.<\/p>\n<p>You can read all of the technical details about the exploit on Qualys <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2022\/01\/25\/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034\">website<\/a>\u00a0if you want to know more about how it works.<\/p>\n<p>Thankfully, several of the major Linux distros have already started rolling out updates to fix the exploit. Both <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5252-1\">Ubuntu<\/a> and\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/lists.debian.org\/debian-security-announce\/2022\/msg00024.html\">Debian 11<\/a> have received patches, and we expect others to follow in short order. Regardless of what Linux distro you use, make sure to run its update tool as soon as you can to make sure you have the latest version with the fix for this exploit.<\/p>\n<\/div>\n<p><!-- .entry-content --><br \/>\n<!-- .entry-footer -->\n<\/div>\n<p><script>\n setTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s) } (window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n   fbq('init', '335401813750447');\n   fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.howtogeek.com\/782149\/12-year-old-linux-vulnerability-grants-root-access\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#12-Year-Old Linux Vulnerability Grants Root Access&#8221; fatmawati achmad zaenuri\/Shutterstock.com Sometimes, it can take a long time before a vulnerability is exploited. In the case of this Polkit (fka PolicyKit) issue, we\u2019re talking about a 12-year-old bug that\u2019s just been discovered and shown off in a proof of concept. According to researchers at Qualys, this Polkit&#8230;<\/p>\n","protected":false},"author":1,"featured_media":399830,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2019\/06\/Linux-laptop-showing-a-bash-prompt.jpg?height=200p&trim=2,2,2,2","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-399829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/399829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=399829"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/399829\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/399830"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=399829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=399829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=399829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}