Логотип exploitDog
bind: "CVE-2021-4034"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2021-4034"

Количество 17

Количество 17

ubuntu логотип

CVE-2021-4034

больше 3 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Высокий
redhat логотип

CVE-2021-4034

больше 3 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Высокий
nvd логотип

CVE-2021-4034

больше 3 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Высокий
msrc логотип

CVE-2021-4034

больше 3 лет назад

CVSS3: 7.8
EPSS: Высокий
debian логотип

CVE-2021-4034

больше 3 лет назад

A local privilege escalation vulnerability was found on polkit's pkexe ...

CVSS3: 7.8
EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2022:0190-1

больше 3 лет назад

Security update for polkit

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:0191-1

больше 3 лет назад

Security update for polkit

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:0190-1

больше 3 лет назад

Security update for polkit

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:0189-1

больше 3 лет назад

Security update for polkit

EPSS: Высокий
rocky логотип

RLSA-2022:267

больше 3 лет назад

Important: polkit security update

EPSS: Высокий
github логотип

GHSA-qgr2-xgqv-24x8

больше 3 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Высокий
oracle-oval логотип

ELSA-2022-9073

больше 3 лет назад

ELSA-2022-9073: polkit security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0274

больше 3 лет назад

ELSA-2022-0274: polkit security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0267

больше 3 лет назад

ELSA-2022-0267: polkit security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2022-00488

больше 3 лет назад

Уязвимость библиотеки Polkit и инструмента песочницы Bubblewrap, вызванная переполнением буфера на стеке, позволяющая нарушителю повысить свои привилегии до уровня суперпользователя

CVSS3: 7.8
EPSS: Высокий
redos логотип

ROS-20220301-01

больше 3 лет назад

Уязвимость инструмента песочницы Bubblewrap

EPSS: Высокий
redos логотип

ROS-20220128-01

больше 3 лет назад

Уязвимость библиотеки Polkit

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
88%
Высокий
больше 3 лет назад
redhat логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
88%
Высокий
больше 3 лет назад
nvd логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
88%
Высокий
больше 3 лет назад
msrc логотип
CVSS3: 7.8
88%
Высокий
больше 3 лет назад
debian логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexe ...

CVSS3: 7.8
88%
Высокий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0190-1

Security update for polkit

88%
Высокий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0191-1

Security update for polkit

88%
Высокий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0190-1

Security update for polkit

88%
Высокий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0189-1

Security update for polkit

88%
Высокий
больше 3 лет назад
rocky логотип
RLSA-2022:267

Important: polkit security update

88%
Высокий
больше 3 лет назад
github логотип
GHSA-qgr2-xgqv-24x8

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
88%
Высокий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-9073

ELSA-2022-9073: polkit security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2022-0274

ELSA-2022-0274: polkit security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2022-0267

ELSA-2022-0267: polkit security update (IMPORTANT)

больше 3 лет назад
fstec логотип
BDU:2022-00488

Уязвимость библиотеки Polkit и инструмента песочницы Bubblewrap, вызванная переполнением буфера на стеке, позволяющая нарушителю повысить свои привилегии до уровня суперпользователя

CVSS3: 7.8
88%
Высокий
больше 3 лет назад
redos логотип
ROS-20220301-01

Уязвимость инструмента песочницы Bubblewrap

88%
Высокий
больше 3 лет назад
redos логотип
ROS-20220128-01

Уязвимость библиотеки Polkit

88%
Высокий
больше 3 лет назад

Уязвимостей на страницу