HomeSecurityChasing the pwnkit vulnerability (CVE-2021-4034) on Linux

Hunting down the pwnkit vulnerability (CVE-2021-4034) on Linux

In November 2021, a vulnerability was discovered in a ubiquitous Linux module called Polkit. Polkit, developed by Red Hat, facilitates communication between privileged and unprivileged processes on Linux endpoints. Due to a flaw in a component of Polkit — pkexec — a local privilege escalation vulnerability exists that could allow someone to transform from a standard user to root.

See also: LockBit ransomware: Linux version targets VMware ESXi servers

Linux

Once initial access is gained through other means, exploiting CVE-2021-4032 — nicknamed “pwnkit” — is easy, and a proof of concept is available. Mitigation and update recommendations can be found on the Red Hat website.

Pwnkit was publicly revealed on January 25, 2022.

See also: CWP bugs allow root code execution on Linux servers

Hunting for pwnkit using CrowdStrike Falcon

To hunt down pwnkit, we will use two different methods. First, we will profile the processes spawned by pkexec, and second, we will target a signal absent from pkeexec process executions that could indicate that exploitation has occurred.

Profiling pkexec

When pwnkit is called by a non-privileged user, pkexec will accept armed instructions and create a new process as the root user. On a Linux system, the root user has User ID (UID) 0. Visually, the attack path looks like this:

Hunting down the pwnkit vulnerability (CVE-2021-4034) on Linux

To cast the widest possible net, we will look at the processes that pkexec typically spawns and look for outliers. Our query will look something like this:

index=main sourcetype=ProcessRollup2* event_simpleName=ProcessRollup2 event_platform=Lin | search ParentBaseFileName=pkexec AND UID_decimal=0
| stats values(CommandLine) as CommandLine, count(aid) as executionCount by aid, ComputerName, ParentBaseFileName, FileName, UID_decimal | sort + executionCount

The output of this query will be similar to this:

Linux

Right at the top, we can see two low-velocity executions of interest. The second one we immediately recognize as legitimate. The first one is an exploitation of the pwnkit usage and deserves further attention.

The public proof of concept code used for this tutorial issues a fixed command: /bin/sh-pi. Hunting for this command line in particular may uncover lazy testing and/or exploitation, but be aware that this string is trivial to modify:

index=main sourcetype=ProcessRollup2* event_simpleName=ProcessRollup2 event_platform=Lin | search ParentBaseFileName=pkexec AND UID_decimal=0 AND CommandLine="/bin/sh -pi"
| stats values(CommandLine) as CommandLine, count(aid) as executionCount by aid, ComputerName, ParentBaseFileName, FileName, UID_decimal | sort + executionCount

See also: Significant increase in malware targeting Linux machines in 2021

Blank command lines in pkexec

One of the interesting artifacts of the pwnkit exploitation is the absence of a command line argument when invoking pkexec. You can see it here:

Linux

Additionally, the process requesting elevation and pwnkit leverage will not have a UID of 0. Therefore, a pkeexec execution that has been done will have a Real User ID (RUID) value that is not 0. With this information, we can look for instances of pkeexec invoked with a null value on the command line and a RUID other than 0.

index=main sourcetype=ProcessRollup2* event_simpleName=ProcessRollup2 event_platform=Lin | search FileName=pkexec AND RUID_decimal!=0
| where isnull(CommandLine) | stats dc(aid) as totalEndpoints count(aid) as detectionCount, values(ComputerName) as endpointNames by ParentBaseFileName, FileName, UID_decimal | sort - detectionCount

With this query, all our tests focus on:

Hunting down the pwnkit vulnerability (CVE-2021-4034) on Linux

Any of the above queries can be scheduled for bulk reporting or turned into custom IOAs for real-time hunting, detection and/or prevention.

Linux

Information source: crowdstrike.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS