CVE-2021-4034

HIGH KEV RANSOMWARE LAB

Local Privilege Escalation in polkits pkexec

Title source: metasploit

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Exploits (175)

exploitdb WORKING POC
by Lance Biggerstaff · textlocallinux
https://www.exploit-db.com/exploits/50689
nomisec WORKING POC 2,027 stars
by berdav · local
https://github.com/berdav/CVE-2021-4034
nomisec WORKING POC 1,283 stars
by ly4k · local
https://github.com/ly4k/PwnKit
nomisec WORKING POC 1,125 stars
by arthepsy · local
https://github.com/arthepsy/CVE-2021-4034
nomisec WORKING POC 346 stars
by PwnFunction · local
https://github.com/PwnFunction/CVE-2021-4034
nomisec WORKING POC 26 stars
by c3c · local
https://github.com/c3c/CVE-2021-4034
nomisec WORKING POC 19 stars
by dadvlingd · local
https://github.com/dadvlingd/CVE-2021-4034
nomisec WORKING POC 12 stars
by chenaotian · local
https://github.com/chenaotian/CVE-2021-4034
nomisec WORKING POC 10 stars
by wudicainiao · local
https://github.com/wudicainiao/cve-2021-4034
nomisec WORKING POC 8 stars
by rvizx · local
https://github.com/rvizx/CVE-2021-4034
nomisec WORKING POC 4 stars
by Y3A · local
https://github.com/Y3A/CVE-2021-4034
nomisec WORKING POC 4 stars
by tahaafarooq · local
https://github.com/tahaafarooq/poppy
nomisec WORKING POC 4 stars
by TheJoyOfHacking · local
https://github.com/TheJoyOfHacking/berdav-CVE-2021-4034
nomisec WORKING POC 3 stars
by artemis-mike · local
https://github.com/artemis-mike/cve-2021-4034
nomisec WRITEUP 2 stars
by wechicken456 · poc
https://github.com/wechicken456/CVE-2021-4034-CTF-writeup
nomisec WORKING POC 2 stars
by Pixailz · local
https://github.com/Pixailz/CVE-2021-4034
nomisec WORKING POC 2 stars
by Nosferatuvjr · local
https://github.com/Nosferatuvjr/PwnKit
gitlab WORKING POC 1 stars
by FR4NC0X · poc
https://gitlab.com/FR4NC0X/pwnkit-helper
nomisec SUSPICIOUS 1 stars
by kaisen-bot · poc
https://github.com/kaisen-bot/pwnkit-helper
nomisec WORKING POC 1 stars
by jscamposx · poc
https://github.com/jscamposx/hack
nomisec WORKING POC 1 stars
by zaaraZiof0 · local
https://github.com/zaaraZiof0/pkexec-exploit-CVE
nomisec WORKING POC 1 stars
by dr4xp · local
https://github.com/dr4xp/pwnkit-helper
nomisec WORKING POC 1 stars
by CYB3RK1D · local
https://github.com/CYB3RK1D/CVE-2021-4034-POC
nomisec WORKING POC 1 stars
by mutur4 · local
https://github.com/mutur4/CVE-2021-4034
nomisec WORKING POC 1 stars
by cdxiaodong · local
https://github.com/cdxiaodong/CVE-2021-4034-touch
nomisec WORKING POC 1 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2021-4034_Python3
nomisec WORKING POC 1 stars
by A1vinSmith · local
https://github.com/A1vinSmith/CVE-2021-4034
nomisec STUB 1 stars
by xcanwin · poc
https://github.com/xcanwin/CVE-2021-4034-UniontechOS
nomisec WORKING POC 1 stars
by jcatala · remote
https://github.com/jcatala/f_poc_cve-2021-4034
nomisec WORKING POC
by Murguii · poc
https://github.com/Murguii/DEV-CVE-2021-4034
nomisec WRITEUP
by vaibhavkrishna12004 · poc
https://github.com/vaibhavkrishna12004/ubuntu-privesc-lab
nomisec WORKING POC
by devianntsec · poc
https://github.com/devianntsec/CVE-2021-4034-PwnKit-Masters-Thesis
nomisec WORKING POC
by Allu-mette · poc
https://github.com/Allu-mette/cve-2021-4034
nomisec WORKING POC
by Abbykito · poc
https://github.com/Abbykito/KERNELexploits
gitlab WORKING POC
by zoobab · poc
https://gitlab.com/zoobab/cve-2021-4034
gitlab WORKING POC
by Tramadol · local
https://gitlab.com/Tramadol/cve-2021-4034
gitlab SCANNER
by i7ach1 · poc
https://gitlab.com/i7ach1/pwnkit-cve-2021-4034
gitlab WORKING POC
by RekGRpth · local
https://gitlab.com/RekGRpth/CVE-2021-4034
nomisec WORKING POC
by ramahmdr · local
https://github.com/ramahmdr/PwnKit
nomisec WRITEUP
by boro03 · poc
https://github.com/boro03/CVE-2021-4034
nomisec WRITEUP
by BugVex · poc
https://github.com/BugVex/Poison-HTB-Report
nomisec WORKING POC
by Milad-Rafie · local
https://github.com/Milad-Rafie/PwnKit-Local-Privilege-Escalation-Vulnerability-Discovered-in-polkit-s-pkexec-CVE-2021-4034
nomisec WORKING POC
by kali-guru · poc
https://github.com/kali-guru/Pwnkit-CVE-2021-4034
nomisec WORKING POC
by Z3R0space · poc
https://github.com/Z3R0space/CVE-2021-4034
nomisec WORKING POC
by Z3R0-0x30 · local
https://github.com/Z3R0-0x30/CVE-2021-4034
nomisec WORKING POC
by AsierEgana · local
https://github.com/AsierEgana/cve-2021-4034
nomisec WORKING POC
by ikerSandoval003 · local
https://github.com/ikerSandoval003/CVE-2021-4034
nomisec WORKING POC
by marcosChoucino · poc
https://github.com/marcosChoucino/CVE-2021-4034
nomisec WORKING POC
by igonzalez357 · local
https://github.com/igonzalez357/CVE-2021-4034-PwnKit-
nomisec WORKING POC
by nagorealbisu · local
https://github.com/nagorealbisu/CVE-2021-4034
nomisec WORKING POC
by 12bijaya · local
https://github.com/12bijaya/CVE-2021-4034-PwnKit-
nomisec STUB
by dh4r4 · poc
https://github.com/dh4r4/PwnKit-CVE-2021-4034-
nomisec WORKING POC
by EuJin03 · local
https://github.com/EuJin03/CVE-2021-4034-PoC
nomisec STUB
by zxybfq · poc
https://github.com/zxybfq/CVE-2021-4034
nomisec WORKING POC
by ps-interactive · local
https://github.com/ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection
nomisec WORKING POC
by evkl1d · local
https://github.com/evkl1d/CVE-2021-4034
nomisec WRITEUP
by LucasPDiniz · local
https://github.com/LucasPDiniz/CVE-2021-4034
nomisec WORKING POC
by X-Projetion · local
https://github.com/X-Projetion/Exploiting-PwnKit-CVE-2021-4034-
nomisec WORKING POC
by supportingmx · poc
https://github.com/supportingmx/cve-2021-4034
nomisec WORKING POC
by Part01-Pai · poc
https://github.com/Part01-Pai/Polkit-Permission-promotion-compiled
nomisec WRITEUP
by ASG-CASTLE · poc
https://github.com/ASG-CASTLE/CVE-2021-4034
nomisec WORKING POC
by FancySauce · local
https://github.com/FancySauce/PwnKit-CVE-2021-4034
nomisec WORKING POC
by Pol-Ruiz · local
https://github.com/Pol-Ruiz/CVE-2021-4034
nomisec WORKING POC
by cerodah · local
https://github.com/cerodah/CVE-2021-4034
nomisec WORKING POC
by JohnGilbert57 · local
https://github.com/JohnGilbert57/CVE-2021-4034-Capture-the-flag
nomisec WORKING POC
by asepsaepdin · local
https://github.com/asepsaepdin/CVE-2021-4034
github FAILED
by velikrgl · cpoc
https://github.com/velikrgl/CVE-Exploits/tree/main/CVE-2021-4034
nomisec WORKING POC
by pyhrr0 · poc
https://github.com/pyhrr0/pwnkit
nomisec WORKING POC
by fei9747 · local
https://github.com/fei9747/CVE-2021-4034
nomisec WORKING POC
by galoget · local
https://github.com/galoget/PwnKit-CVE-2021-4034
nomisec WORKING POC
by toecesws · poc
https://github.com/toecesws/CVE-2021-4034
nomisec WORKING POC
by antoinenguyen-09 · local
https://github.com/antoinenguyen-09/CVE-2021-4034
nomisec WORKING POC
by Geni0r · poc
https://github.com/Geni0r/cve-2021-4034-poc
nomisec WORKING POC
by Silencecyber · poc
https://github.com/Silencecyber/cve-2021-4034
nomisec WORKING POC
by HellGateCorp · local
https://github.com/HellGateCorp/pwnkit
github FAILED
by CaraTortu · pythonpoc
https://github.com/CaraTortu/CVE_POCs/tree/main/CVE-2021-4034
nomisec WORKING POC
by CronoX1 · local
https://github.com/CronoX1/CVE-2021-4034
nomisec SUSPICIOUS
by TanmoyG1800 · poc
https://github.com/TanmoyG1800/CVE-2021-4034
nomisec WORKING POC
by 0x4ndy · local
https://github.com/0x4ndy/CVE-2021-4034-PoC
nomisec WORKING POC
by TotallyNotAHaxxer · local
https://github.com/TotallyNotAHaxxer/CVE-2021-4034
nomisec WORKING POC
by tzwlhack · local
https://github.com/tzwlhack/CVE-2021-4034
github FAILED
by venkyr · cpoc
https://github.com/venkyr/cve-pocs/tree/main/CVE-2021-4034
vulncheck_xdb WORKING POC
remote
https://github.com/milot/dissecting-pkexec-cve-2021-4034
vulncheck_xdb WORKING POC
remote
https://github.com/0x05a/my-cve-2021-4034-poc
vulncheck_xdb WORKING POC
local
https://github.com/deep-know/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/TomSgn/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/nel0x/pwnkit-vulnerability
vulncheck_xdb WORKING POC
local
https://github.com/edsonjt81/CVE-2021-4034-Linux
vulncheck_xdb WORKING POC
local
https://github.com/ITMarcin2211/Polkit-s-Pkexec-CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/defhacks/cve-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Jesrat/make_me_root
vulncheck_xdb WORKING POC
local
https://github.com/Squirre17/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/movvamrocks/PwnKit-CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Tanmay-N/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/LJP-TW/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/ck00004/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/x04000/AutoPwnkit
vulncheck_xdb FAILED
local
https://github.com/x04000/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/DanaEpp/pwncat_pwnkit
vulncheck_xdb WORKING POC
local
https://github.com/an0n7os/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/FDlucifer/Pwnkit-go
vulncheck_xdb WORKING POC
local
https://github.com/Joffr3y/Polkit-CVE-2021-4034-HLP
vulncheck_xdb WORKING POC
local
https://github.com/drapl0n/pwnKit
vulncheck_xdb WORKING POC
local
https://github.com/G01d3nW01f/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Ankit-Ojha16/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/HrishitJoshi/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/scent2d/PoC-CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux
vulncheck_xdb WORKING POC
local
https://github.com/Almorabea/pkexec-exploit
vulncheck_xdb WORKING POC
local
https://github.com/navisec/CVE-2021-4034-PwnKit
vulncheck_xdb WORKING POC
local
https://github.com/0x01-sec/CVE-2021-4034-
vulncheck_xdb WORKING POC
local
https://github.com/OXDBXKXO/ez-pwnkit
vulncheck_xdb WORKING POC
local
https://github.com/TW-D/PwnKit-Vulnerability_CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/v-rzh/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/glowbase/PwnKit-CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Kirill89/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Rvn0xsy/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/oreosec/pwnkit
vulncheck_xdb WORKING POC
local
https://github.com/Yakumwamba/POC-CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/JoyGhoshs/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/jpmcb/pwnkit-go
vulncheck_xdb WORKING POC
local
https://github.com/pengalaman-1t/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/EstamelGG/CVE-2021-4034-NoGCC
vulncheck_xdb WORKING POC
local
https://github.com/Fato07/Pwnkit-exploit
vulncheck_xdb WORKING POC
local
https://github.com/deoxykev/CVE-2021-4034-Rust
vulncheck_xdb WORKING POC
local
https://github.com/DosAmp/pkwned
vulncheck_xdb WORKING POC
local
https://github.com/Plethore/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/luckythandel/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/NiS3x/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/nikip72/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/ashutoshrohilla/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Al1ex/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/callrbx/pkexec-lpe-poc
vulncheck_xdb WORKING POC
local
https://github.com/vilasboasph/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/phvilasboas/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Anonymous-Family/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/luijait/PwnKit-Exploit
vulncheck_xdb WORKING POC
local
https://github.com/joeammond/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/robemmerson/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/whokilleddb/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/sunny0day/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/PeterGottesman/pwnkit-exploit
vulncheck_xdb WORKING POC
local
https://github.com/fdellwing/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/san3ncrypt3d/CVE-2021-4034-POC
vulncheck_xdb WORKING POC
local
https://github.com/c3l3si4n/pwnkit
vulncheck_xdb WORKING POC
local
https://github.com/moldabekov/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/aus-mate/CVE-2021-4034-POC
vulncheck_xdb WORKING POC
local
https://github.com/LukeGix/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Nero22k/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/N1et/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/kimusan/pkwner
vulncheck_xdb WORKING POC
local
https://github.com/Immersive-Labs-Sec/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/zhzyker/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/wongwaituck/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/ayypril/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/An00bRektn/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Ayrx/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/mebeim/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/nikaiw/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/dzonerzy/poc-cve-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/Audiobahn/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/gbrsh/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/clubby789/CVE-2021-4034
vulncheck_xdb WORKING POC
local
https://github.com/ryaagard/CVE-2021-4034
metasploit WORKING POC EXCELLENT
by Qualys Security, Andris Raugulis, Dhiraj Mishra, bwatters-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2021_4034_pwnkit_lpe_pkexec.rb

Scores

CVSS v3 7.8
EPSS 0.8881
EPSS Percentile 99.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull kalilinux/kali-rolling:latest
docker pull vulhub/polkit:0.105
docker pull kalilinux/kali-rolling
+156 more repos

Details

CISA KEV 2022-06-27
VulnCheck KEV 2022-06-07
InTheWild.io 2022-06-27
ENISA EUVD EUVD-2021-33934
Ransomware Use Confirmed
CWE
CWE-125 CWE-787
Status published
Products (50)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
canonical/ubuntu_linux 21.10
oracle/http_server 12.2.1.3.0
oracle/http_server 12.2.1.4.0
oracle/zfs_storage_appliance_kit 8.8
polkit_project/polkit < 121
redhat/enterprise_linux 8.0
... and 40 more
Published Jan 28, 2022
KEV Added Jun 27, 2022
Tracked Since Feb 18, 2026