CVE-2021-4034 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 94.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-07-18.
Description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 94.35% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | yes — remediate by 2022-07-18 |
| Public exploit | yes |
| Published | 2022-01-28 |
| Last modified | 2026-08-15 |
CISA KEV
| Name | Red Hat Polkit Out-of-Bounds Read and Write Vulnerability |
|---|---|
| Added | 2022-06-27 |
| Due | 2022-07-18 |
| Vendor / product | Red Hat / Polkit |
| Ransomware use | known |
Affected (31)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| oracle | http server |
| oracle | zfs storage appliance kit |
| polkit project | polkit |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for ibm z systems eus |
| redhat | enterprise linux for power big endian |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux for power little endian eus |
| redhat | enterprise linux for scientific computing |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux server update services for sap solutions |
| redhat | enterprise linux workstation |
| siemens | scalance lpe9403 |
| siemens | scalance lpe9403 firmware |
| siemens | sinumerik edge |
| starwindsoftware | command center |
| starwindsoftware | starwind virtual san |
| suse | enterprise storage |
| suse | linux enterprise desktop |
| suse | linux enterprise high performance computing |
| suse | linux enterprise server |
| suse | linux enterprise workstation extension |
| suse | manager proxy |
| suse | manager server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PolicyKit-1 0.105-31 - Privilege Escalation | 2022-01-27 |
References
- http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html
- https://access.redhat.com/security/vulnerabilities/RHSB-2022-001
- https://bugzilla.redhat.com/show_bug.cgi?id=2025869
- https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf
- https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
- https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/
- https://www.starwindsoftware.com/security/sw-20220818-0001/
- https://www.suse.com/support/kb/doc/?id=000020564
- http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html
- https://access.redhat.com/security/vulnerabilities/RHSB-2022-001
- https://bugzilla.redhat.com/show_bug.cgi?id=2025869
- https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf
- https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
- https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/
→ the Explorer · watch your stack · NVD