peter bassill · operator
$ cve CVE-2021-4034 JSON

CVE-2021-4034 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 94.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-07-18.

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS94.35% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-07-18
Public exploityes
Published2022-01-28
Last modified2026-08-15

CISA KEV

NameRed Hat Polkit Out-of-Bounds Read and Write Vulnerability
Added2022-06-27
Due2022-07-18
Vendor / productRed Hat / Polkit
Ransomware useknown

Affected (31)

VendorProduct
canonicalubuntu linux
oraclehttp server
oraclezfs storage appliance kit
polkit projectpolkit
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux server update services for sap solutions
redhatenterprise linux workstation
siemensscalance lpe9403
siemensscalance lpe9403 firmware
siemenssinumerik edge
starwindsoftwarecommand center
starwindsoftwarestarwind virtual san
suseenterprise storage
suselinux enterprise desktop
suselinux enterprise high performance computing
suselinux enterprise server
suselinux enterprise workstation extension
susemanager proxy
susemanager server

Public exploits

SourceTitleDate
exploit-dbPolicyKit-1 0.105-31 - Privilege Escalation2022-01-27

References

→ the Explorer  ·  watch your stack  ·  NVD