Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-4034

98
FAUCET Score

CVE-2021-4034, also known as PwnKit, is a local privilege escalation vulnerability in the polkit pkexec utility, affecting various Linux distributions including Canonical, Oracle, Red Hat, and SUSE. This flaw allows an unprivileged local attacker to gain administrative rights by manipulating environment variables, causing pkexec to execute arbitrary code. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 100/100, it presents a significant threat due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available on Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage, including warnings from CISA.

Impacted Technologies

VendorProductVersion(s)CPE
< 121CPE matchmatch criteria
cpe:2.3:a:polkit_project:polkit:*:*:*:*:*:*:*:*
7.6CPE matchmatch criteria
cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.6:*:*:*:*:*:*:*
7.7CPE matchmatch criteria
cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.7:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
94.92%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Jun 27, 2022
Metasploit: Local Privilege Escalation in polkits pkexec · Jan 25, 2022
ExploitDB: EDB-50689 · Jan 27, 2022
This CVE's current EPSS score of 0.9492 is in the 100th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
View patch
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: 18898-16820Fixed in: 0.116-6
microsoftpatch availablevia msrc
Product: 18906-16823Fixed in: 0.119-2
microsoftpatch availablevia msrc
Product: cbl2 polkit 0.119-2 on CBL Mariner 2.0Fixed in: 0.119-2
microsoftpatch availablevia msrc
Product: cm1 polkit 0.116-6 on CBL Mariner 1.0Fixed in: 0.116-6
mongodbpatch availablevia llm_extracted
View patch
oraclepatch availablevia nvd_reference
View patch
qdrantpatch availablevia llm_extracted
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: polkit-0:0.115-11.el8_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: polkit-0:0.115-11.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.21-20220126.0.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.10-202202081536_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: polkit-0:0.115-9.el8_1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle SupportFixed in: polkit-0:0.96-11.el6_10.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: polkit-0:0.112-26.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: polkit-0:0.112-12.el7_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: polkit-0:0.112-12.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)Fixed in: polkit-0:0.112-18.el7_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Telco Extended Update SupportFixed in: polkit-0:0.112-18.el7_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsFixed in: polkit-0:0.112-18.el7_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Advanced Update SupportFixed in: polkit-0:0.112-22.el7_7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Telco Extended Update SupportFixed in: polkit-0:0.112-22.el7_7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsFixed in: polkit-0:0.112-22.el7_7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: polkit-0:0.115-13.el8_5.1
View patch
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted

Vendor Advisories (12)

qdrantllm-qdrant-eb49b38e311782d4

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
consulllm-consul-68677bda49a5d5ba

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
clamavllm-clamav-3eab9d86927798d6

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
boschllm-bosch-61f82770ccde5428

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
freshrssllm-freshrss-d56e7a0dd71e3861

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
barracudallm-barracuda-5071a3dbc991b6aa

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
symantecllm-symantec-8a8f862f2e25be57

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
verbbllm-verbb-8168edbfdb0b386b

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Jan 29, 2022
redhatCVE-2021-4034Important

polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector

Jan 25, 2022
microsoft2022-Jan/CVE-2021-4034Important

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Jan 11, 2022
mongodbllm-mongodb-5623024ff9843f09

pkexec privilege escalation vulnerability (CVE-2021-4034)

boschllm-bosch-b32fc3f82ec31e57

Pkexec privilege escalation vulnerability (CVE-2021-4034)

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
vicarius.io / vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034
ExploitThird Party Advisory
packetstormsecurity.com / files/166196/Polkit-pkexec-Local-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/166200/Polkit-pkexec-Privilege-Escalation.html
Third Party AdvisoryVDB Entry
access.redhat.com / security/vulnerabilities/RHSB-2022-001
MitigationVendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatch
cert-portal.siemens.com / productcert/pdf/ssa-330556.pdf
Third Party Advisory
gitlab.freedesktop.org / polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
Patch
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
qualys.com / 2022/01/25/cve-2021-4034/pwnkit.txt
ExploitMitigationThird Party Advisory
secpod.com / blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034
ExploitThird Party Advisory
starwindsoftware.com / security/sw-20220818-0001
Third Party Advisory
suse.com / support/kb/doc
Third Party Advisory