CVE
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When
Exploitation IoCs 6
Domain hermes-results
Filename .journald-cache.php
Filename HiveCmd.jar
Filename hive_rce_py2.py
IP 103[.]97[.]0[.]57
Package Hades
MITRE ATT&CK TTPs 8
T1059.001 T1068 T1071.004 T1090 T1133 T1210 T1220 T1566
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
DNS
Command And Control
Proxy
Command And Control
External Remote Services
Persistence
Exploitation of Remote Services
Lateral Movement
XSL Script Processing
Defense Evasion
Phishing
Initial Access