CVE-2021-3560 is a critical privilege escalation vulnerability in Polkit, affecting various Linux distributions including Canonical, Debian, and Red Hat. This flaw allows an unprivileged local attacker to bypass D-Bus credential checks, gaining root access to the system. With a CVSS score of 7.8 (High), it poses significant risks to data confidentiality, integrity, and system availability, requiring only low privileges and no user interaction to exploit. The vulnerability is actively exploited in the wild, with public exploit code available via Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.119CPE matchmatch criteria | cpe:2.3:a:polkit_project:polkit:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
20.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to for example create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Feb 8, 2022polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()
Jun 3, 2021