{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"Polkit pkexec Local Privilege Escalation Vulnerability (CVE-2021-4034)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2022-00001","status":"final","version":"31","initial_release_date":"2022-01-26T10:00:00+00:00","current_release_date":"2026-07-28T01:14:07.325099+00:00","revision_history":[{"date":"2022-01-26T10:00:00+00:00","number":"31","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2022-00001"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2021-4034"}],"notes":[{"category":"summary","text":"On 25 January 2022, researchers at Qualys revealed a memory corruption vulnerability in Polkit’s pkexec tool, present in most major Linux distributions since 2009. An attacker with local access to a vulnerable system could exploit this vulnerability to elevate their privileges to root. Polkit (previously known as PolicyKit) is used for inter-process communication between privileged and non-privileged processes on Linux systems. The pkexec command is used by authorized users to execute commands at elevated privileges (like using sudo).\n\nWatchGuard has determined that none of our products and services are vulnerable to CVE-2021-4034 (PwnKit).","title":"Summary"}]}}