peter bassill · operator
$ cve CVE-2021-3560 JSON

CVE-2021-3560 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 23.7% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2023-06-02.

Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS23.71% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-863
On CISA KEVyes — remediate by 2023-06-02
Public exploityes
Published2022-02-16
Last modified2026-06-17

CISA KEV

NameRed Hat Polkit Incorrect Authorization Vulnerability
Added2023-05-12
Due2023-06-02
Vendor / productRed Hat / Polkit
Ransomware usenone reported

Affected (7)

VendorProduct
canonicalubuntu linux
debiandebian linux
polkit projectpolkit
redhatenterprise linux
redhatopenshift container platform
redhatvirtualization
redhatvirtualization host

Public exploits

SourceTitleDate
exploit-dbPolkit 0.105-26 0.117-2 - Local Privilege Escalation2021-06-15

References

→ the Explorer  ·  watch your stack  ·  NVD