cbcvebase.
CVE-2021-4034
published 2022-01-28

CVE-2021-4034: A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users…

PriorityP192high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
94.92%
99.9th percentile
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Affected

80 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
debianpolicykit-1< policykit-1 0.105-31.1 (bookworm)policykit-1 0.105-31.1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 41f6ea5b9aaa28b740d47ffe995a5013211fdbb041f6ea5b9aaa28b740d47ffe995a5013211fdbb0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 98e0c7c702894987732776736c99b85ade6fba4598e0c7c702894987732776736c99b85ade6fba45
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b50fb8dbc8b81aaa126387de428f4c42a7c72a73b50fb8dbc8b81aaa126387de428f4c42a7c72a73
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1fe82bfd9e4ce93399d815ca458b58505191c3e81fe82bfd9e4ce93399d815ca458b58505191c3e8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 27a6f495b63a1804cc71be45911065db7757a98c27a6f495b63a1804cc71be45911065db7757a98c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1290eb4412aa0f0e9f3434b406dc8e255da85f9e1290eb4412aa0f0e9f3434b406dc8e255da85f9e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a8054d3fa5deb84b215d6be1b910a978f3cb840da8054d3fa5deb84b215d6be1b910a978f3cb840d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cfbfff8ce5e3d674947581f1eb9af0a1b1807950cfbfff8ce5e3d674947581f1eb9af0a1b1807950
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dcd46d897adb70d63e025f175a00a89797d31a43dcd46d897adb70d63e025f175a00a89797d31a43
linuxlinux_kernel< 4.9.3174.9.317
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.10 < 4.14.2824.14.282
linuxlinux_kernel>= 4.15 < 4.19.2464.19.246
linuxlinux_kernel>= 4.20 < 5.4.1975.4.197

Detection & IOCsextracted from sources · hover to see the quote

path/var/log/auth.log
  • Monitor /var/log/auth.log for suspicious pkexec-related entries when investigating potential CVE-2021-4034 exploitation.
  • CVE-2021-4034 (PwnKit) is actively exploited in the wild by threat actors including perfctl cryptomining malware and nation-state groups (Earth Krahang, CL-STA-0969/Liminal Panda) for Linux privilege escalation — prioritize patching polkit/pkexec on internet-facing Linux systems.
  • The exploit abuses environment variable reintroduction in pkexec to load an attacker-controlled shared library with root privileges — monitor for unexpected shared library loads by pkexec.
  • ·The vulnerability exists in all versions of pkexec since its first distribution in 2009 — any unpatched Linux system with polkit installed is affected regardless of whether the polkit daemon is running.
  • ·Exploitation does not require the polkit daemon to be running — any unprivileged local user can exploit pkexec even in minimal environments.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.