Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

KEV · Activement exploitée

CVE-2021-4034

CVE-2021-4034 est activement exploitée (catalogue CISA KEV) : sévérité high (CVSS 7.8), 0 apps suivies concernées, aucune encore exposée en version courante.

Gravité (CVSS)
7.8

Échelle NVD

Exploitation
Avérée

CISA KEV · EPSS prédit 94.9 %

Apps suivies
0
Encore exposées
0
Exploit public : ExploitDB

EN A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Vecteur d'attaque : Local Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 94.92% modèle prédictif ; la CISA constate une exploitation avérée percentile 99.9%

CISA Known Exploited Vulnerability

Ajouté au KEV
2022-06-27
Deadline remédiation
2022-07-18
Action requise
Apply updates per vendor instructions.
Ransomware
Inconnu (non documenté par CISA)
Voir sur NVD ↗ Catalogue CISA KEV ↗ Advisory · access.redhat.com Advisory · bugzilla.redhat.com Advisory · gitlab.freedesktop.org