cbcvebase.
CVE-2021-3560
published 2022-02-16

CVE-2021-3560: It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debianpolicykit-1< policykit-1 0.105-31 (bookworm)policykit-1 0.105-31 (bookworm)
msrccm1_polkit_0.116-6_on_cbl_mariner_1.0
polkit_projectpolkit< 0.1190.119
polkit_projectpolkit
redhatopenshift_container_platform
redhatvirtualization
redhatvirtualization_host

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH