WGSA-2022-00001#
Polkit pkexec Local Privilege Escalation Vulnerability (CVE-2021-4034)
Summary #
On 25 January 2022, researchers at Qualys revealed a memory corruption vulnerability in Polkit’s pkexec tool, present in most major Linux distributions since 2009. An attacker with local access to a vulnerable system could exploit this vulnerability to elevate their privileges to root. Polkit (previously known as PolicyKit) is used for inter-process communication between privileged and non-privileged processes on Linux systems. The pkexec command is used by authorized users to execute commands at elevated privileges (like using sudo).
WatchGuard has determined that none of our products and services are vulnerable to CVE-2021-4034 (PwnKit).
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2021-4034 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | — |
Product status #
| Product | Affected | Not affected |
|---|
Solution #
No solution has been published for this advisory.