KEVIntel
7.8
CVSS
High

CVE-2021-4034

PUBLISHED

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow...

Exploited in the wild Low complexity No user interaction
Vendor
freedesktop.org
Product
polkit
Published
Jan 28, 2022
EPSS

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

cisa metasploit nessus_scanner

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-06-27 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jun 27, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

cve_2021_4034_pwnkit_lpe_pkexec

metasploit · Created Unknown

Metasploit module for CVE-2021-4034

ASG-CASTLE/CVE-2021-4034

github · Created 2024-04-19 04:33:14 UTC · 0 stars

wechicken456/CVE-2021-4034-CTF-writeup

github · Created 2024-02-04 19:00:38 UTC · 2 stars

Pixailz/CVE-2021-4034

github · Created 2022-10-10 22:56:09 UTC · 2 stars

polkit priv esc: pkexec out of boundary exploit

TheJoyOfHacking/berdav-CVE-2021-4034

github · Created 2022-03-23 11:08:20 UTC · 4 stars

LJP-TW/CVE-2021-4034

github · Created 2022-02-17 13:17:07 UTC · 2 stars

pkexec EoP exploit

ck00004/CVE-2021-4034

github · Created 2022-02-15 02:34:48 UTC · 28 stars

CVE-2021-4034 centos8可用版本

x04000/CVE-2021-4034

github · Created 2022-02-13 11:37:43 UTC · 3 stars

A simple PWNKIT file to convert you to root

rvizx/CVE-2021-4034

github · Created 2022-02-04 18:31:15 UTC · 8 stars

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python

navisec/CVE-2021-4034-PwnKit

github · Created 2022-01-30 03:08:51 UTC · 5 stars

PwnKit PoC for Polkit pkexec CVE-2021-4034

sofire/polkit-0.96-CVE-2021-4034

github · Created 2022-01-29 06:54:49 UTC · 8 stars

centos 6.10 rpm for fix polkit CVE-2021-4034; centos 6.10的rpm包,修复CVE-2021-4034 漏洞

NeonWhiteRabbit/CVE-2021-4034

github · Created 2022-01-28 18:12:54 UTC · 18 stars

Pwnkit Exploit (CVE-2021-4034), no download capabilty? Copy and paste it!

Kirill89/CVE-2021-4034

github · Created 2022-01-28 15:16:44 UTC · 6 stars

pkexec (Polkit) exploit of Privilege Escalation vulnerability CVE-2021-4034

Rvn0xsy/CVE-2021-4034

github · Created 2022-01-28 15:13:28 UTC · 97 stars

CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation

Yakumwamba/POC-CVE-2021-4034

github · Created 2022-01-28 13:04:22 UTC · 5 stars

NeonWhiteRabbit/CVE-2021-4034-BASH-One-File-Exploit

github · Created 2022-01-28 03:58:34 UTC · 2 stars

CVE-2021-4034 - One line in the terminal for an instant priv esc to boxes that are vulnerable. See usage.

EstamelGG/CVE-2021-4034-NoGCC

github · Created 2022-01-28 02:54:38 UTC · 79 stars

CVE-2021-4034简单优化,以应对没有安装gcc和make的目标环境

c3c/CVE-2021-4034

github · Created 2022-01-27 17:43:24 UTC · 25 stars

Pre-compiled builds for CVE-2021-4034

deoxykev/CVE-2021-4034-Rust

github · Created 2022-01-27 16:28:56 UTC · 2 stars

Linux LPE using polkit-1 written in Rust.

locksec/CVE-2021-4034

github · Created 2022-01-27 16:15:21 UTC · 2 stars

Exploit PoC for the polkit pkexec (PWNKIT) vulnerability

PwnFunction/CVE-2021-4034

github · Created 2022-01-27 14:43:57 UTC · 344 stars

Proof of concept for pwnkit vulnerability

thatstraw/CVE-2021-4034

github · Created 2022-01-27 09:35:54 UTC · 2 stars

NiS3x/CVE-2021-4034

github · Created 2022-01-27 08:28:56 UTC · 1 stars

PoC CVE 2021-4034 PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec

Al1ex/CVE-2021-4034

github · Created 2022-01-27 02:27:15 UTC · 4 stars

Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)

cd80-ctf/CVE-2021-4034

github · Created 2022-01-27 01:14:11 UTC · 2 stars

A simple proof-of-concept for CVE-2021-4034 (pkexec local privilege escalation)

nobelh/CVE-2021-4034

github · Created 2022-01-26 20:32:10 UTC · 0 stars

Polkit pkexec CVE-2021-4034 Proof Of Concept and Patching

Anonymous-Family/CVE-2021-4034

github · Created 2022-01-26 18:53:47 UTC · 2 stars

Linux system service bug gives root on all major distros, exploit published A vulnerability in the pkexec component of Polkit identified as CVE-2021-4034 PwnKit is present in the default configuration of all major Linux distributions and can be exploited to gain privileges over the compj researchers.

joeammond/CVE-2021-4034

github · Created 2022-01-26 17:53:16 UTC · 165 stars

Python exploit code for CVE-2021-4034 (pwnkit)

dadvlingd/CVE-2021-4034

github · Created 2022-01-26 16:43:18 UTC · 19 stars

whokilleddb/CVE-2021-4034

github · Created 2022-01-26 16:18:10 UTC · 4 stars

An exploit for CVE-2021-4034 aka Pwnkit: Local Privilege Escalation in polkit's pkexec

n3rdh4x0r/CVE-2021-4034

github · Created 2022-01-26 13:45:17 UTC · 0 stars

chenaotian/CVE-2021-4034

github · Created 2022-01-26 10:58:23 UTC · 11 stars

CVE-2021-4034 POC and Docker and Analysis write up

zhzyker/CVE-2021-4034

github · Created 2022-01-26 07:19:21 UTC · 45 stars

polkit pkexec Local Privilege Vulnerability to Add custom commands

An00bRektn/CVE-2021-4034

github · Created 2022-01-26 04:58:16 UTC · 11 stars

A Golang implementation of clubby789's implementation of CVE-2021-4034

Y3A/CVE-2021-4034

github · Created 2022-01-26 04:05:50 UTC · 4 stars

Ayrx/CVE-2021-4034

github · Created 2022-01-26 03:33:47 UTC · 93 stars

Exploit for CVE-2021-4034

mebeim/CVE-2021-4034

github · Created 2022-01-26 03:20:18 UTC · 28 stars

CVE-2021-4034: Local Privilege Escalation in polkit's pkexec proof of concept

nikaiw/CVE-2021-4034

github · Created 2022-01-26 02:02:25 UTC · 62 stars

PoC for CVE-2021-4034

Audiobahn/CVE-2021-4034

github · Created 2022-01-26 01:09:32 UTC · 9 stars

CVE-2021-4034 🎧

JohnHammond/CVE-2021-4034

github · Created 2022-01-26 01:05:55 UTC · 15 stars

Bash implementation of CVE-2021-4034

arthepsy/CVE-2021-4034

github · Created 2022-01-26 00:56:36 UTC · 1078 stars

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)

gbrsh/CVE-2021-4034

github · Created 2022-01-26 00:53:19 UTC · 2 stars

clubby789/CVE-2021-4034

github · Created 2022-01-26 00:28:52 UTC · 6 stars

berdav/CVE-2021-4034

github · Created 2022-01-25 23:51:37 UTC · 1990 stars

CVE-2021-4034 1day

ryaagard/CVE-2021-4034

github · Created 2022-01-25 23:11:30 UTC · 72 stars

Local Privilege Escalation in polkit's pkexec

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit