Room Banner
Back to all walkthroughs
Room Icon

Pwnkit: CVE-2021-4034

Max room.

Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package

info

15 min

17,902

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

-2021-4034 (colloquially dubbed "Pwnkit") is a terrifying Local Privilege Escalation (LPE) vulnerability, located in the "Polkit" package installed by default on almost every major distribution of the operating system (as well as many other *nix operating systems). In other words, it affects virtually every mainstream system on the planet.

This room will provide an overview of the vulnerability, as well as recommendations to patch affected systems. A vulnerable machine has also been attached to allow you to try the vulnerability for yourself!

Without further ado, let's begin.

Answer the questions below
Deploy the machine by clicking on the green "Deploy" button at the top of this task!