CVE-2021-4034

high

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

References

https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html

https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html

https://securelist.com/container-security-typical-issues/119974/

https://thehackernews.com/2025/08/chinese-hackers-murky-genesis-and.html

https://securityaffairs.com/180737/apt/nation-state-group-cl-sta-0969-targeted-southeast-asian-telecoms-in-2024.html

https://thehackernews.com/2025/08/cl-sta-0969-installs-covert-malware-in.html

https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/

https://www.edgescan.com/wp-content/uploads/2024/03/2023-Vulnerability-Statistics-Report.pdf

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a

https://www.bleepingcomputer.com/news/security/linux-malware-perfctl-behind-years-long-cryptomining-campaign/

https://www.aquasec.com/blog/perfctl-a-stealthy-malware-targeting-millions-of-linux-servers

https://securelist.com/vulnerability-exploit-report-q2-2024/113455/

https://securityaffairs.com/164838/breaking-news/excobalt-cybercrime-group-targets-russian-orgs.html

https://thehackernews.com/2024/06/excobalt-cyber-gang-targets-russian.html

https://www.crowdstrike.com/blog/anatomy-of-alpha-spider-ransomware/

https://thehackernews.com/2024/02/fritzfrog-returns-with-log4shell-and.html

https://www.bleepingcomputer.com/news/security/privilege-elevation-exploits-used-in-over-50-percent-of-insider-attacks/

https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/

https://github.com/nicoibarburu/CVE-2021-4034

https://github.com/jeffmarlonmandela/CVE-2021-4034-PwnKit

https://github.com/snowflakeovo/internal-privesc-poc

https://github.com/keenglomerate/bastion_ai

https://github.com/OleksandrBlack/cve_centos

https://github.com/ropydev/CVE-2021-4034-PwnKit

https://github.com/Erik-Castro/DevSecurity

https://github.com/kryptbakar/Enumeration-Vulnerability-Analysis

https://github.com/Leemyunglyul/cve-2021-4034-mock

https://github.com/naim-ali27/TryHackMe-CTF-Writeups

https://github.com/vorkampfer/pwnkit_safety_check

https://github.com/B1gN0Se/PwnKit_CVE-2021-4034

https://github.com/nextgensoumen/soc-pulse

https://github.com/Murguii/DEV-CVE-2021-4034

https://github.com/Sweatzer/Lab-WriteUps

https://github.com/vaibhavkrishna12004/ubuntu-privesc-lab

https://github.com/strikoder/LinEnum-ng

https://github.com/SyedNabeel98/CVE-writeups

https://github.com/Abbykito/KERNELexploits

https://github.com/ramahmdr/PwnKit

https://github.com/iliasszrq/Scanner-Local-de-Vulnerabilites

https://github.com/CerberusMrX/Cerberus-React2Shell-Scanner-Exploit

https://github.com/boro03/CVE-2021-4034

https://github.com/V0idA2tronaut/CVEs

https://github.com/zaaraZiof0/pkexec-exploit-CVE

https://github.com/kaisen-bot/pwnkit-helper

https://github.com/dr4xp/pwnkit-helper

https://github.com/BugVex/Poison-HTB-Report

https://github.com/kali-guru/Pwnkit-CVE-2021-4034

https://github.com/jlucas8/cve-test-scripts

https://github.com/ziggsanon/Threat-Detection-CVE-Analysis-Lab-with-Wazuh-SIEM-XDR-

https://github.com/Z3R0-0x30/CVE-2021-4034

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/Chrisync/CVE-Scanner

https://github.com/oieramelibia/DEV_Practica_CVE_2021_4034

https://github.com/ikerSandoval003/CVE-2021-4034

https://github.com/marcosChoucino/CVE-2021-4034

https://github.com/igonzalez357/CVE-2021-4034-PwnKit-

https://github.com/nagorealbisu/CVE-2021-4034

https://github.com/12bijaya/CVE-2021-4034-PwnKit-

https://github.com/dh4r4/PwnKit-CVE-2021-4034-

https://github.com/CyberSecAI/cve_info_refs_crawler

https://github.com/sarperavci/ExploitMe

https://github.com/lsclsclsc/CVE-2021-4034

https://github.com/gek64/cve

https://github.com/OpenCVEs/cve-template

https://github.com/h0pe-ay/Vulnerability-Reproduction

https://github.com/justikail/root

https://github.com/velikrgl/CVE-Exploits

https://github.com/Zeyad-Azima/Remedy4me

https://github.com/z3dc0ps/ROCKING-CVE

https://github.com/flux10n/CVE-2021-4034

https://github.com/wjl110/CVE-Master

https://github.com/Naughty-SEC/pkexec-shell-executor

https://github.com/A1vinSmith/CVE-2021-4034

https://github.com/CaraTortu/POCs

https://github.com/antoinenguyen-09/CVE-2021-4034

https://github.com/karaname/pkexec-exploit

https://github.com/rhin0cer0s/CVE-2021-4034

https://github.com/qasj/CVE-2021-4034

https://github.com/1izardd/CVE-2021-4034

https://github.com/z3dc0ps/awesome-linux-exploits

https://github.com/Nosferatuvjr/PwnKit

https://github.com/Pajarraco4444/CVE-2021-4034

https://github.com/azazelm3dj3d/CVE-2021-4034

https://github.com/OpenCVEs/CVE-2021-4034

https://github.com/nel0x/pwnkit-vulnerability

https://github.com/GatoGamer1155/CVE-2021-4034

https://github.com/T3slaa/pwnkit-pwn

https://github.com/defhacks/cve-2021-4034

https://github.com/chenaotian/CVE-2022-0185

https://github.com/ck00004/CVE-2021-4034

https://github.com/hohn/codeql-sample-polkit

https://github.com/x04000/AutoPwnkit

https://github.com/DanaEpp/pwncat_pwnkit

https://github.com/FDlucifer/Pwnkit-go

https://github.com/ziadsaleemi/polkit_CVE-2021-4034

https://github.com/Joffr3y/Polkit-CVE-2021-4034-HLP

https://github.com/drapl0n/pwnKit

https://github.com/drapl0n/dawnKit

https://github.com/Ph4nt0mh4x0r/auto-CVE-2021-4034

https://github.com/xuntitled/Polkit-pkexec-exploit-for-Linux

https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux

https://github.com/Almorabea/pkexec-exploit

https://github.com/OXDBXKXO/go-PwnKit

https://github.com/OXDBXKXO/ez-pwnkit

https://github.com/codiobert/pwnkit-scanner

https://github.com/sofire/polkit-0.96-CVE-2021-4034

https://github.com/n3onhacks/CVE-2021-4034

https://github.com/Kirill89/CVE-2021-4034

https://github.com/Rvn0xsy/CVE-2021-4034

https://github.com/oreosec/pwnkit

https://github.com/jpmcb/pwnkit-go

https://github.com/n3onhacks/CVE-2021-4034-BASH-One-File-Exploit

https://github.com/EstamelGG/CVE-2021-4034-NoGCC

https://github.com/0xalwayslucky/log4j-polkit-poc

https://github.com/Fato07/Pwnkit-exploit

https://github.com/c3c/CVE-2021-4034

https://github.com/evdenis/lsm_bpf_check_argc0

https://github.com/Plethore/CVE-2021-4034

https://github.com/ashutoshrohilla/CVE-2021-4034

https://github.com/Al1ex/CVE-2021-4034

https://github.com/nobelh/CVE-2020-4034

https://github.com/hackingyseguridad/CVE-2021-4034

https://github.com/Anonymous-Family/CVE-2021-4034

https://github.com/joeammond/CVE-2021-4034

https://github.com/whokilleddb/CVE-2021-4034

https://github.com/azminawwar/CVE-2021-4034

https://github.com/xcanwin/CVE-2021-4034-UniontechOS

https://github.com/ly4k/PwnKit

https://github.com/moldabekov/CVE-2021-4034

https://github.com/N1et/CVE-2021-4034

https://github.com/An00bRektn/CVE-2021-4034

https://github.com/Ayrx/CVE-2021-4034

https://github.com/signfind/CVE-2021-4034

https://github.com/Audiobahn/CVE-2021-4034

https://github.com/JohnHammond/CVE-2021-4034

https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034

https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683

https://bugzilla.redhat.com/show_bug.cgi?id=2025869

https://access.redhat.com/security/vulnerabilities/RHSB-2022-001

http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html

Details

Source: Mitre, NVD

Published: 2022-01-28

Updated: 2026-08-15

Named Vulnerability: PwnKitKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.94921