CVE-2021-4034
Description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
In plain language
AI Act nowCVE-2021-4034 is a serious local security flaw in polkit’s pkexec tool that can let an attacker take higher privileges on Linux systems, and because it’s already known to be exploited and public exploits exist, most small businesses running the listed Linux distributions should act urgently.
What to do
- Update your systems to the latest security updates from your Linux vendor—especially the polkit package that includes pkexec. 2) Check whether any of the affected distributions/editions you run are present (Astra Linux, Debian, Ubuntu, Fedora, CentOS, РЕД ОС, polkit community packages, and the named “ФССП” OS). 3) If you manage these machines, ask your IT/admin team to confirm the patch is applied and that no known-vulnerable pkexec remains installed.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministryen·The Hacker News· Incident Hermes AI agent ai-ml
- Operation Escaneo Signals Shift in LatAm Threat Landscapeen·Dark Reading· Research MexicanMafia data-breach
- What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security anden-us·Kaspersky Securelist· Research Kaspersky Container Security rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-4034 and every CVE in our database. Create a free account — no credit card required.
Create Free Account