Skip to main content

CVE detail

CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS 7.8 · HighBuzz score 90.5KEV listed4 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 90.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 18.0
Mention score
30.0
24 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
18.0
4 repos · best confidence 0.99
Best PoC traction
2
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
3
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
24 source links · newest first
  • ed inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit ( CVE-2021-4034 ), the sudo heap overflow ( CVE-2021-3156 ), and the long-standing IIS WebDAV vulnerability ( CVE-2017-7269 ). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems en

    newssecurityaffairs.comJul 24, 2026, 12:10 PM
  • QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P

    vendorblog.qualys.comJul 14, 2026, 6:00 PM
  • QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P

    vendorblog.qualys.comJul 8, 2026, 10:15 PM
  • In-depth analysis of threat activity we call CL-UNK-1068. We discuss their toolset, including tunneling, reconnaissance and credential theft.

    vendorunit42.paloaltonetworks.comMar 6, 2026, 11:00 AM
  • State-backed group CL-STA-0969 hit Southeast Asian telecoms in 2024, targeting critical infrastructure, says Palo Alto Networks’ Unit 42. Palo Alto Networks reported that a nation-state actor, tracked as CL-STA-0969, targeted telecom firms in Southeast Asia, with attacks on critical infrastructure from February to November 2024. Threat actor CL-STA-0969 overlaps with the China-linked cyber espionage group […]

    newssecurityaffairs.comAug 4, 2025, 7:29 AM
  • Recent activity targeting telecom infrastructure is assessed with high confidence to overlap with Liminal Panda activity. The actors used custom tools, tunneling and OPSEC tactics for stealth.

    vendorunit42.paloaltonetworks.comJul 29, 2025, 9:00 PM
  • Thousands of Linux systems are likely infected with the highly elusive and persistent “perfctl” (or “perfcc“) cryptomining malware and many others still could be at risk of getting compromised, Aqua Security researchers revealed last week. “In all the attacks observed, the malware was used to run a cryptominer, and in some cases, we also detected the execution of proxy-jacking software,” they shared. “Perfctl” malware Though the actual cryptomining is performed by XMRIG Monero cryptomining software, … More →

    newswww.helpnetsecurity.comOct 7, 2024, 12:34 PM
  • The cybercrime group ExCobalt targeted Russian organizations in multiple sectors with a previously unknown backdoor known as GoRed. Positive Technologies researchers reported that a cybercrime gang called ExCobalt targeted Russian organizations in multiple sectors with a previously unknown Golang-based backdoor known as GoRed. Members of the ExCobalt group have been active since at least 2016, […]

    newssecurityaffairs.comJun 24, 2024, 7:36 AM
  • The FritzFrog cryptomining botnet has new potential for growth: a recently analyzed variant of the bot is exploiting the Log4Shell (CVE-2021-44228) and PwnKit (CVE-2021-4034) vulnerabilities for lateral movement and privilege escalation. The FritzFrog botnet The FritzFrog botnet, initially identified in August 2020, is a peer-to-peer (rather than centrally-controlled) botnet powered by malware written in Golang. It targets SSH servers by brute-forcing login credentials, and has managed to compromise thousands of them worldwide. “Each compromised host … More →

    newswww.helpnetsecurity.comFeb 1, 2024, 3:21 PM
  • Researchers from Sysdig are warning of an ongoing attack campaign against vulnerable GitLab servers that results in deployment of cryptojacking and proxyjacking malware. The attacks use cross-platform malware, kernel rootkits, and multiple layers of obfuscation and try to evade detection by abusing legitimate services. “This operation was much more sophisticated than many of the attacks […]

    newswww.csoonline.comAug 17, 2023, 8:01 PM
  • CISA added a Linux kernel vulnerability, tracked as CVE-2021-3493, to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week added a Linux kernel vulnerability, tracked as CVE-2021-3493, to its Known Exploited Vulnerabilities Catalog. According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the […]

    newssecurityaffairs.comOct 21, 2022, 1:47 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a Linux kernel flaw to its Known Exploited Vulnerabilities Catalog and instructed federal agencies to address it within three weeks.

    newswww.securityweek.comOct 21, 2022, 10:28 AM
  • Cisco’s Talos security researchers warn of a newly identified attack framework and its associated remote access trojan (RAT) targeting Windows, Linux, and macOS systems.

    newswww.securityweek.comOct 14, 2022, 12:57 PM
  • Researchers have discovered a new attack framework of Chinese origin that they believe is being used in the wild. The framework is made up of a command-and-control (C2) backend dubbed Alchimist and an accompanying customizable remote access Trojan (RAT) for Windows and Linux machines. The framework can also be used to generate PowerShell-based attack shellcode […]

    newswww.csoonline.comOct 13, 2022, 5:52 PM
  • Experts discovered a new attack framework, including a C2 tool dubbed Alchimist, used in attacks against Windows, macOS, and Linux systems. Researchers from Cisco Talos discovered a new, previously undocumented attack framework that included a C2 dubbed Alchimist. The framework is likely being used in attacks aimed at Windows, macOS, and Linux systems. The experts […]

    newssecurityaffairs.comOct 13, 2022, 2:59 PM
  • Security researchers with AT&T Alien Labs are warning of a new piece of malware that can take full control of infected Linux systems, including Internet of Things (IoT) devices.

    newswww.securityweek.comSep 8, 2022, 6:01 PM
  • A new Linux malware dubbed Shikitega leverages a multi-stage infection chain to target endpoints and IoT devices. Researchers from AT&T Alien Labs discovered a new piece of stealthy Linux malware, dubbed Shikitega, that targets endpoints and IoT devices. The malware stands out for its multistage infection chain, threat actors use it to gain full control of the system […]

    newssecurityaffairs.comSep 7, 2022, 4:38 PM
  • Researchers from the AT&T Alien Labs Resarch have discovered a new and stealthy Linux malware it’s dubbed Shikitega. Once it’s on…

    newswww.malwarebytes.comSep 6, 2022, 5:00 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) says a Linux vulnerability tracked as CVE-2021-4034 and PwnKit has been exploited in attacks.

    newswww.securityweek.comJun 28, 2022, 4:43 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: PolKit vulnerability can give attackers root on many Linux distros (CVE-2021-4034) A memory corruption vulnerability (CVE-2021-4034) in PolKit, a component used in major Linux distributions and some Unix-like operating systems, can be easily exploited by local unprivileged users to gain full root privileges. DazzleSpy: macOS backdoor delivered through watering hole attacks In late 2021, a never before seen macOS backdoor was … More →

    newswww.helpnetsecurity.comJan 30, 2022, 9:00 AM
  • Security researchers have found a privilege escalation vulnerability in pkexec, a tool that’s present by default on many Linux installations. The flaw, called PwnKit, could allow attackers to easily gain root privileges on systems if they have access to a regular user without administrative privileges. Researchers from security firm Qualys who discovered and reported the […]

    newswww.csoonline.comJan 26, 2022, 2:50 PM
  • Qualys security researchers warn of an easily exploitable privilege escalation vulnerability in polkit’s pkexec, a SUID-root program found in all Linux distributions.

    newswww.securityweek.comJan 26, 2022, 12:31 PM
  • A flaw in Polkit’s pkexec component, tracked as CVE-2021-4034 (PwnKit) can be exploited to gain full root privileges on major Linux distros. An attacker can exploit a vulnerability in Polkit’s pkexec component, tracked as CVE-2021-4034, that affects all major Linux distributions to gain full root privileges on the system. The good news is that this […]

    newssecurityaffairs.comJan 26, 2022, 11:12 AM
  • A memory corruption vulnerability (CVE-2021-4034) in PolKit, a component used in major Linux distributions and some Unix-like operating systems, can be easily exploited by local unprivileged users to gain full root privileges. While the vulnerability is not exploitable remotely and doesn’t, in itself, allow arbitrary code execution, it can be used by attackers that have already gained a foothold on a vulnerable host to escalate their privileges and achieve that capability. About the vulnerability (CVE-2021-4034) … More →

    newswww.helpnetsecurity.comJan 26, 2022, 9:44 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

4 repository references · best confidence 0.99 · max 2 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence