← Vulnerability feed

Vulnerability record · CVE-2021-4034 · published 28 January 2022

CVE-2021-4034: polkit pkexec argument handling flaw allows local root escalation

Polkit Project · Polkit

pkexec, the setuid polkit utility for running commands as privileged users, mishandles the calling parameter count and ends up treating environment variables as commands. This out-of-bounds read and write lets a local unprivileged user induce pkexec to execute arbitrary code. Because pkexec is setuid and widely shipped across major Linux distributions, any local foothold can be turned into administrative rights.

7.8 CVSS 3.1 High CISA KEV since 27 Jun 2022 Known ransomware use EPSS 94% · top 0.2% CWE-787 · Out-of-bounds writeCWE-125 · Out-of-bounds read
7.8CVSS 3.1 base score, v2 7.2
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
30Affected product versions listed by NVD
24References, 7 tagged exploit
15 Aug 2026Last modified by NVD

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityA locally exploitable setuid flaw giving root, with public exploit code, KEV listing and ransomware association, and an EPSS probability above 0.94.

What it is

pkexec, the setuid polkit utility for running commands as privileged users, mishandles the calling parameter count and ends up treating environment variables as commands. This out-of-bounds read and write lets a local unprivileged user induce pkexec to execute arbitrary code. Because pkexec is setuid and widely shipped across major Linux distributions, any local foothold can be turned into administrative rights.

Impact

An attacker with an unprivileged local account gains administrative (root) rights on the target machine. That enables full control of the host, including credential access, persistence and lateral movement.

Attack surface

Reached locally by executing the setuid pkexec binary with crafted environment variables; no network access, no authentication and no user interaction are required beyond the ability to run a process as an unprivileged user. The CVSS vector AV:L/AC:L/PR:L/UI:N confirms local, low-complexity, low-privilege, no-interaction exploitation.

Exploitation

Listed in CISA KEV with a due date of 2022-07-18 and flagged for known ransomware campaign use, and EPSS is 0.94921 (99.856th percentile). Multiple references are tagged Exploit, including the Qualys PwnKit writeup and Packet Storm entries, so public exploit code exists.

What to do

  • Apply vendor patches for polkit/pkexec (for example the upstream freedesktop commit and Red Hat, Oracle, SUSE, Siemens and StarWind advisories) as the first action.
  • If patching cannot be done immediately, remove the setuid bit from pkexec or restrict its execution to trusted users, per vendor mitigation guidance.
  • Inventory all Linux hosts and images for the affected pkexec binary and track them to a patched state.
  • Limit and monitor local interactive access, since exploitation requires only an unprivileged local account.
  • Re-check container and appliance images that bundle polkit, as they may carry the vulnerable binary.

Detection

  • Alert on execution of pkexec by non-root users, especially with unusual or empty environment variables.
  • Monitor process trees where pkexec spawns unexpected child processes or shells.
  • Watch for privilege changes to uid 0 originating from pkexec outside normal administrative workflows.
  • Hunt for known PwnKit exploit artifacts and command patterns referenced in public exploit writeups.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-4034 to the Known Exploited Vulnerabilities catalog on 27 June 2022 as "Red Hat Polkit Out-of-Bounds Read and Write Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.

Affected products

30 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html Third Party AdvisoryVDB Entry
https://access.redhat.com/security/vulnerabilities/RHSB-2022-001 MitigationVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2025869 Issue TrackingPatch
https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf Third Party Advisory
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683 Patch
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt ExploitMitigationThird Party Advisory
https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/ ExploitThird Party Advisory
https://www.starwindsoftware.com/security/sw-20220818-0001/ Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020564 Third Party Advisory
http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html Third Party AdvisoryVDB Entry
https://access.redhat.com/security/vulnerabilities/RHSB-2022-001 MitigationVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2025869 Issue TrackingPatch
https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf Third Party Advisory
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683 Patch
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt ExploitMitigationThird Party Advisory
https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/ ExploitThird Party Advisory
https://www.starwindsoftware.com/security/sw-20220818-0001/ Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020564 Third Party Advisory
https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034 ExploitThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034 US Government Resource

Track CVE-2021-4034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed9.8CVE-2018-14667RichFaces Framework EL injection enables unauthenticated remote code executionRichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language injection through the UserResource resource. A remote, unauthenticated att…KEVEPSS 74%analysed9.8CVE-2018-6789Exim SMTP base64d buffer overflow allows remote code executionExim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the f…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2021-4034), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.