Vulnerability record · CVE-2021-3560 · published 16 February 2022
CVE-2021-3560: polkit D-Bus credential check bypass allows local root escalation
Polkit Project · Polkit
polkit can be tricked into bypassing credential checks for D-Bus requests, letting an unprivileged local user elevate to root. Because polkit is a core authorization component on many Linux distributions, a local foothold can be turned into full administrative control of the host.
Description
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to root with a public exploit and KEV listing, but it requires an existing local foothold rather than remote reach.
What it is
polkit can be tricked into bypassing credential checks for D-Bus requests, letting an unprivileged local user elevate to root. Because polkit is a core authorization component on many Linux distributions, a local foothold can be turned into full administrative control of the host.
Impact
An attacker gains root privileges, enabling creation of a new local administrator account and full read/write access to data plus the ability to disrupt system availability.
Attack surface
Reached locally through D-Bus requests to polkit; the CVSS vector shows local access (AV:L) with low privileges (PR:L) and no user interaction (UI:N). No remote or network vector is described.
Exploitation
Listed in CISA KEV since 2023-05-12 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.23708 (97.7th percentile). A public exploit write-up is referenced, so exploitation is established and active.
What to do
- Apply vendor polkit updates for your distribution (Red Hat, Debian, Ubuntu, Canonical) per the vendor advisory and KEV required action.
- Restrict local interactive access and audit accounts with shell or D-Bus access on multi-user hosts.
- Monitor for unexpected creation of local administrator or sudo-capable accounts.
- Where patching is delayed, limit exposure by reducing untrusted local users on affected systems.
Detection
- Alert on new or modified accounts in /etc/passwd, /etc/shadow and sudoers files outside change windows.
- Monitor process ancestry where polkit or dbus-daemon spawns shells or administrative tools unexpectedly.
- Audit D-Bus method calls to polkit from non-privileged UIDs for anomalous patterns.
- Track host-level privilege escalation events correlated with recent local logins.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-3560 to the Known Exploited Vulnerabilities catalog on 12 May 2023 as "Red Hat Polkit Incorrect Authorization Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 June 2023.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.html | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.html | Third Party AdvisoryVDB Entry |
| https://bugzilla.redhat.com/show_bug.cgi?id=1961710 | Issue TrackingPatchVendor Advisory |
| https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.html | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.html | Third Party AdvisoryVDB Entry |
| https://bugzilla.redhat.com/show_bug.cgi?id=1961710 | Issue TrackingPatchVendor Advisory |
| https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3560 | US Government Resource |
Track CVE-2021-3560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.