7.8
CVE-2021-4034 (PwnKit)
- EPSS 94.92%
- Veröffentlicht 28.01.2022 20:15:12
- Zuletzt bearbeitet 15.08.2026 04:17:57
- Erkennungen
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Polkit Project ≫ Polkit Version < 121
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 7.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.2
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0
Redhat ≫ Enterprise Linux For Power Little Endian Version 7.0
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.1
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.2
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Enterprise Linux For Scientific Computing Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Eus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Workstation Version 7.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 21.10
Suse ≫ Enterprise Storage Version 7.0
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp2 SwEdition -
Suse ≫ Manager Proxy Version 4.1
Suse ≫ Manager Server Version 4.1
Suse ≫ Linux Enterprise Desktop Version 15 Update sp2
Suse ≫ Linux Enterprise Server Version 15 Update sp2 SwPlatform -
Suse ≫ Linux Enterprise Server Version 15 Update sp2 SwPlatform sap
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp5
Oracle ≫ HTTP Server Version 12.2.1.3.0
Oracle ≫ HTTP Server Version 12.2.1.4.0
Oracle ≫ Zfs Storage Appliance Kit Version 8.8
Siemens ≫ Sinumerik Edge Version < 3.3.0
Siemens ≫ Scalance Lpe9403 Firmware Version < 2.0
Starwindsoftware ≫ Command Center Version 1.0 Update update3_build5871
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build14338
27.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
SchwachstelleThe Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 94.92% | 0.999 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://bugzilla.redhat.com/show_bug.cgi?id=2025869
https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/
https://www.starwindsoftware.com/security/sw-20220818-0001/
https://www.suse.com/support/kb/doc/?id=000020564
https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034
http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html
http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html
https://access.redhat.com/security/vulnerabilities/RHSB-2022-001
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034