TROYANOSYVIRUS
Volver a CVEs

CVE-2021-4034

HIGHCISA KEV
7.8

Descripcion

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Detalles CVE

Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado1/28/2022
Ultima modificacion11/6/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorRed Hat
ProductoPolkit
Nombre vulnerabilidadRed Hat Polkit Out-of-Bounds Read and Write Vulnerability
Fecha inclusion KEV2022-06-27
Fecha limite remediacion2022-07-18
Uso en ransomwareUnknown

Productos afectados

canonical:ubuntu_linuxoracle:http_serveroracle:zfs_storage_appliance_kitpolkit_project:polkitredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_eusredhat:enterprise_linux_for_ibm_z_systemsredhat:enterprise_linux_for_ibm_z_systems_eusredhat:enterprise_linux_for_power_big_endianredhat:enterprise_linux_for_power_little_endianredhat:enterprise_linux_for_power_little_endian_eusredhat:enterprise_linux_for_scientific_computingredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_server_tusredhat:enterprise_linux_server_update_services_for_sap_solutionsredhat:enterprise_linux_workstationsiemens:scalance_lpe9403siemens:scalance_lpe9403_firmwaresiemens:sinumerik_edgestarwindsoftware:command_centerstarwindsoftware:starwind_virtual_sansuse:enterprise_storagesuse:linux_enterprise_desktopsuse:linux_enterprise_high_performance_computingsuse:linux_enterprise_serversuse:linux_enterprise_workstation_extensionsuse:manager_proxysuse:manager_server

Debilidades (CWE)

CWE-787CWE-125CWE-787

Referencias

https://bugzilla.redhat.com/show_bug.cgi?id=2025869(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuapr2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.suse.com/support/kb/doc/?id=000020564(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.