CVE-2011-1485 is a race condition vulnerability in the pkexec utility and polkitd daemon within PolicyKit (polkit) versions 0.96 and earlier, primarily affecting Red Hat systems. This flaw allows local users to achieve privilege escalation by exploiting a race condition when pkexec executes a setuid program, using the effective user ID instead of the real user ID. With a CVSS score of 6.9 (High), it presents a significant risk due to its local attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the CISA KEV catalog or Hot List, multiple public exploit modules exist, including Metasploit and ExploitDB entries, indicating readily available exploit code. Despite this, there is no recorded community discussion or media coverage, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.96CPE matchmatch criteria | cpe:2.3:a:redhat:policykit:0.96:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.