Exploit 2021 - Baget

Resource: Baget exploit (2021)

6.1 Logs

Look for:

4. Impact Assessment

| Factor | Assessment | |--------|-------------| | Privileges required | Low (any local user) | | User interaction | None | | Complexity | Low (scriptable, reliable) | | Confidentiality impact | High (read any file) | | Integrity impact | High (modify system) | | Availability impact | High (full system compromise) | baget exploit 2021

A successful exploit allows:


Indicators of compromise (IoCs)

Immediate mitigations (short-term)

References

  1. NVD – CVE-2021-4034: https://nvd.nist.gov/vuln/detail/CVE-2021-4034
  2. Qualys Security Advisory – PwnKit: https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034
  3. Polkit Patch Commit: https://gitlab.freedesktop.org/polkit/polkit/-/commit/7e3526d6f9e2dfb46ad7b637582cf9b7d60e1cdf

End of Report