CVE Tools

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

In plain language

AI Act now

CVE-2021-4034 is a serious local security flaw in polkit’s pkexec tool that can let an attacker take higher privileges on Linux systems, and because it’s already known to be exploited and public exploits exist, most small businesses running the listed Linux distributions should act urgently.

What to do

  1. Update your systems to the latest security updates from your Linux vendor—especially the polkit package that includes pkexec. 2) Check whether any of the affected distributions/editions you run are present (Astra Linux, Debian, Ubuntu, Fedora, CentOS, РЕД ОС, polkit community packages, and the named “ФССП” OS). 3) If you manage these machines, ask your IT/admin team to confirm the patch is applied and that no known-vulnerable pkexec remains installed.

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 22 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Jun 27, 2022
Remediation due:Jul 18, 2022

Required action: Apply updates per vendor instructions.

4 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available
Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Collection
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 48 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2021-4034 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows