CVE-2021-4034
Description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Out-of-bounds Read
DraftCommon Consequences
Applicable Platforms
Out-of-bounds Write
DraftCommon Consequences
Applicable Platforms
PolicyKit-1 0.105-31 - Privilege Escalation
PolicyKit-1 0.105-31 - Privilege Escalation
View Exploit Code →Linux Enterprise Server by Suse
cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:*:-:*:*
Enterprise Linux For Ibm Z Systems Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2:*:*:*:*:*:*:*
Starwind Virtual San by Starwindsoftware
cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build14338:*:*:*:*:*:*
Enterprise Linux Server Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*
Enterprise Linux For Power Big Endian by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Linux Enterprise Workstation Extension by Suse
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp5:*:*:*:*:*:*
Enterprise Linux Desktop by Redhat
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
Enterprise Linux For Scientific Computing by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*
Enterprise Linux Server Update Services For Sap Solutions by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*
Enterprise Linux For Power Little Endian by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*
Enterprise Linux Server Update Services For Sap Solutions by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*
Enterprise Linux Server by Redhat
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
Enterprise Linux For Ibm Z Systems by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*
Enterprise Linux Server Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_eus:8.4:*:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
Enterprise Linux Workstation by Redhat
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Enterprise Linux Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
Enterprise Linux For Ibm Z Systems by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
Linux Enterprise Desktop by Suse
cpe:2.3:o:suse:linux_enterprise_desktop:15:sp2:*:*:*:*:*:*
Enterprise Linux For Ibm Z Systems Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*
Enterprise Linux For Power Little Endian Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
Enterprise Linux For Power Little Endian Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
Manager Proxy by Suse
cpe:2.3:a:suse:manager_proxy:4.1:*:*:*:*:*:*:*
Enterprise Linux Server by Redhat
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
Scalance Lpe9403 Firmware by Siemens
cpe:2.3:o:siemens:scalance_lpe9403_firmware:*:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*
Enterprise Linux Server Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
Http Server by Oracle
cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
Enterprise Linux Server Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
Command Center by Starwindsoftware
cpe:2.3:a:starwindsoftware:command_center:1.0:update3_build5871:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
Enterprise Linux For Power Little Endian by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*
Manager Server by Suse
cpe:2.3:a:suse:manager_server:4.1:*:*:*:*:*:*:*
Enterprise Linux Server Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
Enterprise Linux Server Update Services For Sap Solutions by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*
Enterprise Linux Server Update Services For Sap Solutions by Redhat
cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.6:*:*:*:*:*:*:*
Linux Enterprise High Performance Computing by Suse
cpe:2.3:a:suse:linux_enterprise_high_performance_computing:15.0:sp2:*:*:-:*:*:*
Sinumerik Edge by Siemens
cpe:2.3:a:siemens:sinumerik_edge:*:*:*:*:*:*:*:*
Zfs Storage Appliance Kit by Oracle
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
Http Server by Oracle
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
Enterprise Linux For Power Little Endian Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2:*:*:*:*:*:*:*
Enterprise Linux Server Update Services For Sap Solutions by Redhat
cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.7:*:*:*:*:*:*:*
Polkit by Polkit Project
cpe:2.3:a:polkit_project:polkit:*:*:*:*:*:*:*:*
Enterprise Linux by Redhat
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Linux Enterprise Server by Suse
cpe:2.3:o:suse:linux_enterprise_server:15:sp2:*:*:*:sap:*:*
Enterprise Storage by Suse
cpe:2.3:a:suse:enterprise_storage:7.0:*:*:*:*:*:*:*