ID:7932 - Exploit for Input validation error in polkit - CVE-2021-4034

 
Main Vulnerability Database Exploits ID:7932 - Exploit for Input validation error in polkit - CVE-2021-4034

ID:7932 - Exploit for Input validation error in polkit - CVE-2021-4034

Published: May 31, 2022


Vulnerability identifier: #VU60007
Vulnerability risk: Medium
CVE-ID: CVE-2021-4034
CWE-ID: CWE-20
Exploitation vector: Local access
Vulnerable software:
polkit

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper handling of the calling parameters count in the pkexec setuid binary, which causes the binary to execute environment variables as commands. A local user can craft environment variables in a way that they will be processed and executed by pkexec and execute arbitrary commands on the system as root.


Remediation

Install update from vendor's website.