CVE-2021-4034High· 7.8▾ Abyssal⚠ Exploited in the wildPoC availableA local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 19 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jul 18, 2022
Last analysed / modified upstream
95%
Exploit-DB · 183 GitHub repos · Metasploit ×1 (last check)
Added to the CISA catalog on Jun 27, 2022. Federal remediation due Jul 18, 2022. View catalog ↗
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
polkit < 121enterprise_linux_server_update_services_for_sap_solutions = 7.6enterprise_linux_server_update_services_for_sap_solutions = 7.7enterprise_linux = 8.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 8.2enterprise_linux_for_ibm_z_systems = 7.0enterprise_linux_for_ibm_z_systems = 8.0enterprise_linux_for_ibm_z_systems_eus = 8.2enterprise_linux_for_ibm_z_systems_eus = 8.4enterprise_linux_for_power_big_endian = 7.0enterprise_linux_for_power_little_endian = 7.0enterprise_linux_for_power_little_endian = 8.0enterprise_linux_for_power_little_endian_eus = 8.1enterprise_linux_for_power_little_endian_eus = 8.2enterprise_linux_for_power_little_endian_eus = 8.4enterprise_linux_for_scientific_computing = 7.0enterprise_linux_server = 6.0enterprise_linux_server = 7.0enterprise_linux_server_aus = 7.3enterprise_linux_server_aus = 7.4enterprise_linux_server_aus = 7.6enterprise_linux_server_aus = 7.7enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_eus = 8.4enterprise_linux_server_tus = 7.6enterprise_linux_server_tus = 7.7enterprise_linux_server_tus = 8.2enterprise_linux_server_tus = 8.4enterprise_linux_server_update_services_for_sap_solutions = 8.1enterprise_linux_server_update_services_for_sap_solutions = 8.2enterprise_linux_server_update_services_for_sap_solutions = 8.4enterprise_linux_workstation = 7.0ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 20.04ubuntu_linux = 21.10enterprise_storage = 7.0linux_enterprise_high_performance_computing = 15.0manager_proxy = 4.1manager_server = 4.1linux_enterprise_desktop = 15linux_enterprise_server = 15linux_enterprise_workstation_extension = 12http_server = 12.2.1.3.0http_server = 12.2.1.4.0zfs_storage_appliance_kit = 8.8sinumerik_edge < 3.3.0scalance_lpe9403_firmware < 2.0command_center = 1.0starwind_virtual_san = v8Upgrade past the affected range:
polkit 121sinumerik_edge 3.3.0scalance_lpe9403_firmware 2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-4897Medium· 5.5A flaw was found in polkit
CVE-2025-5777High· 7.5Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2026-0799High· 8.7In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value
CVE-2021-3506High· 7.1An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4
CVE-2023-6610High· 7.1An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel
CVE-2023-3268High· 7.1An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs