LPE in polkit (CVE-2021-4034)

This technique is a Local Privilege Escalation in polkit's pkexec enabling a user to spawn a root shell. The vulnerability is present in all major distros since May 2009. PoC by @bl4sty - https://haxx.in/files/blasty-vs-pkexec.c

Execute this chain

Download Operator (1.7.1)
Learn about Operator

TTPs

Spawn elevated Pneuma via CVE-2021-4034