KEV · Activement exploitée
CVE-2021-3560
CVE-2021-3560 est activement exploitée (catalogue CISA KEV), classée high par l'éditeur : 0 apps suivies concernées, aucune encore exposée en version courante.
- Gravité (CVSS)
- 7.8
- Exploitation
- Avérée
- Apps suivies
- 0
- Encore exposées
- 0
CVSS base ; la gravité est une note éditeur (échelle différente)
CISA KEV · EPSS prédit 22.2 %
Échelle bulletin éditeur : CVSS NVD en attente
Exploit public : ExploitDB
EN It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to for example create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
EPSS
22.19%
modèle prédictif ; la CISA constate une exploitation avérée
percentile 97.5%
CISA Known Exploited Vulnerability
- Ajouté au KEV
- 2023-05-12
- Deadline remédiation
- 2023-06-02
- Action requise
- Apply updates per vendor instructions.
- Ransomware
- Inconnu (non documenté par CISA)