CVE-2021-4034: PwnKit
A local privilege escalation vulnerability in polkit's pkexec utility, present in the default configuration of most Linux distributions since 2009. pkexec fails to properly handle a missing argument count, and a local attacker can abuse that gap together with environment variable injection to have the dynamic loader execute attacker-controlled code with root privileges.
View the authoritative record on NVD ↗Affected software
- polkit pkexec, effectively all versions from May 2009 through the December 2021 fix
How it's exploited
Invoke pkexec with a crafted argument count of zero and manipulated environment variables (such as GCONV_PATH and CHARSET), so pkexec's flawed argument handling causes the dynamic loader to load an attacker-supplied shared module, executing arbitrary code as root with no password or special privileges required.
Severity
CVE-2021-4034 carries a CVSS 3.1 base score of 7.8, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-4034 is categorized under CWE-787, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Apply the distribution's patched polkit package, or as an interim mitigation remove the setuid bit from pkexec (chmod 0755 /usr/bin/pkexec) until patched.
Frequently asked questions
What is CVE-2021-4034?
A local privilege escalation vulnerability in polkit's pkexec utility, present in the default configuration of most Linux distributions since 2009. pkexec fails to properly handle a missing argument count, and a local attacker can abuse that gap together with environment variable injection to have the dynamic loader execute attacker-controlled code with root privileges.
How severe is CVE-2021-4034?
CVE-2021-4034 has a CVSS 3.1 base score of 7.8 out of 10, rated High.
What software is affected by CVE-2021-4034?
CVE-2021-4034 affects polkit pkexec, effectively all versions from May 2009 through the December 2021 fix.
How do you fix CVE-2021-4034?
Apply the distribution's patched polkit package, or as an interim mitigation remove the setuid bit from pkexec (chmod 0755 /usr/bin/pkexec) until patched.
Where is the authoritative record for CVE-2021-4034?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-4034 at https://nvd.nist.gov/vuln/detail/CVE-2021-4034, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest