7.8

CVE-2021-4034 (PwnKit)

Warnung
Medienbericht
Exploit
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Polkit Project ≫ Polkit Version < 121
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 21.10
Suse ≫ Enterprise Storage Version 7.0
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp2 SwEdition -
Suse ≫ Manager Proxy Version 4.1
Suse ≫ Manager Server Version 4.1
Suse ≫ Linux Enterprise Desktop Version 15 Update sp2
Suse ≫ Linux Enterprise Server Version 15 Update sp2 SwPlatform -
Suse ≫ Linux Enterprise Server Version 15 Update sp2 SwPlatform sap
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp5
Oracle ≫ HTTP Server Version 12.2.1.3.0
Oracle ≫ HTTP Server Version 12.2.1.4.0
Siemens ≫ Sinumerik Edge Version < 3.3.0
Siemens ≫ Scalance Lpe9403 Firmware Version < 2.0
   Siemens ≫ Scalance Lpe9403 Version -
Starwindsoftware ≫ Command Center Version 1.0 Update update3_build5871
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build14338

27.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

Schwachstelle

The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.92% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.07.2026 12:48
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2025869
Patch
Issue Tracking
https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf
Third Party Advisory
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
Patch
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
Third Party Advisory
Exploit
Mitigation
https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/
Third Party Advisory
Exploit
https://www.starwindsoftware.com/security/sw-20220818-0001/
Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020564
Third Party Advisory
https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034
Third Party Advisory
Exploit
http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html
Third Party Advisory
VDB Entry
https://access.redhat.com/security/vulnerabilities/RHSB-2022-001
Vendor Advisory
Mitigation
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034
US Government Resource