Pwnkit: Vulnerability in Polkit (CVE-2021-4034) in 5 minutes
Another new CVE that has been making headlines. The CVE-2021-4034 was released a few days ago and has spread like wildfire. I can’t really contribute much more to the topic that hasn’t already been said, but it might be good to give a brief overview of the CVE and how to exploit it (which is trivial).
What is polkit? Polkit is a tool for controlling privileges on Unix-like systems. It can control how unprivileged processes communicate with privileged processes.