CVE-2021-4034, also known as PwnKit, is a local privilege escalation vulnerability in the polkit pkexec utility, affecting various Linux distributions including Canonical, Oracle, Red Hat, and SUSE. This flaw allows an unprivileged local attacker to gain administrative rights by manipulating environment variables, causing pkexec to execute arbitrary code. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 100/100, it presents a significant threat due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available on Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage, including warnings from CISA.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 121CPE matchmatch criteria | cpe:2.3:a:polkit_project:polkit:*:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.6:*:*:*:*:*:*:* | ||
7.7CPE matchmatch criteria | cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.7:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Jan 29, 2022polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
Jan 25, 2022A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Jan 11, 2022pkexec privilege escalation vulnerability (CVE-2021-4034)
Pkexec privilege escalation vulnerability (CVE-2021-4034)