CVE detail
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 18.0
Why it matters now
Mention timeline
- Total mentions
- 3
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
24 source links · newest first
- Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedSecurity Affairs
ed inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit ( CVE-2021-4034 ), the sudo heap overflow ( CVE-2021-3156 ), and the long-standing IIS WebDAV vulnerability ( CVE-2017-7269 ). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems en
newssecurityaffairs.comJul 24, 2026, 12:10 PM QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P
vendorblog.qualys.comJul 14, 2026, 6:00 PM- When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed FirstQualys
QSC Product and Tech Patch Management VMDR Vulnerabilities and Threat Research Patch Tuesday Threat Thursday Top Posts CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) Apache Log4j Zero Day Threat: CVE-2021-44228 Detection and Response Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion) PwnKit: Local P
vendorblog.qualys.comJul 8, 2026, 10:15 PM In-depth analysis of threat activity we call CL-UNK-1068. We discuss their toolset, including tunneling, reconnaissance and credential theft.
vendorunit42.paloaltonetworks.comMar 6, 2026, 11:00 AMState-backed group CL-STA-0969 hit Southeast Asian telecoms in 2024, targeting critical infrastructure, says Palo Alto Networks’ Unit 42. Palo Alto Networks reported that a nation-state actor, tracked as CL-STA-0969, targeted telecom firms in Southeast Asia, with attacks on critical infrastructure from February to November 2024. Threat actor CL-STA-0969 overlaps with the China-linked cyber espionage group […]
newssecurityaffairs.comAug 4, 2025, 7:29 AMRecent activity targeting telecom infrastructure is assessed with high confidence to overlap with Liminal Panda activity. The actors used custom tools, tunneling and OPSEC tactics for stealth.
vendorunit42.paloaltonetworks.comJul 29, 2025, 9:00 PM- Linux systems targeted with stealthy “Perfctl” cryptomining malwareHelp Net Security
Thousands of Linux systems are likely infected with the highly elusive and persistent “perfctl” (or “perfcc“) cryptomining malware and many others still could be at risk of getting compromised, Aqua Security researchers revealed last week. “In all the attacks observed, the malware was used to run a cryptominer, and in some cases, we also detected the execution of proxy-jacking software,” they shared. “Perfctl” malware Though the actual cryptomining is performed by XMRIG Monero cryptomining software, … More →
newswww.helpnetsecurity.comOct 7, 2024, 12:34 PM The cybercrime group ExCobalt targeted Russian organizations in multiple sectors with a previously unknown backdoor known as GoRed. Positive Technologies researchers reported that a cybercrime gang called ExCobalt targeted Russian organizations in multiple sectors with a previously unknown Golang-based backdoor known as GoRed. Members of the ExCobalt group have been active since at least 2016, […]
newssecurityaffairs.comJun 24, 2024, 7:36 AM- FritzFrog botnet exploits Log4Shell, PwnKit vulnerabilitiesHelp Net Security
The FritzFrog cryptomining botnet has new potential for growth: a recently analyzed variant of the bot is exploiting the Log4Shell (CVE-2021-44228) and PwnKit (CVE-2021-4034) vulnerabilities for lateral movement and privilege escalation. The FritzFrog botnet The FritzFrog botnet, initially identified in August 2020, is a peer-to-peer (rather than centrally-controlled) botnet powered by malware written in Golang. It targets SSH servers by brute-forcing login credentials, and has managed to compromise thousands of them worldwide. “Each compromised host … More →
newswww.helpnetsecurity.comFeb 1, 2024, 3:21 PM Researchers from Sysdig are warning of an ongoing attack campaign against vulnerable GitLab servers that results in deployment of cryptojacking and proxyjacking malware. The attacks use cross-platform malware, kernel rootkits, and multiple layers of obfuscation and try to evade detection by abusing legitimate services. “This operation was much more sophisticated than many of the attacks […]
newswww.csoonline.comAug 17, 2023, 8:01 PM- CISA adds Linux kernel flaw CVE-2021-3493 to its Known Exploited Vulnerabilities CatalogSecurity Affairs
CISA added a Linux kernel vulnerability, tracked as CVE-2021-3493, to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week added a Linux kernel vulnerability, tracked as CVE-2021-3493, to its Known Exploited Vulnerabilities Catalog. According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the […]
newssecurityaffairs.comOct 21, 2022, 1:47 PM The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a Linux kernel flaw to its Known Exploited Vulnerabilities Catalog and instructed federal agencies to address it within three weeks.
newswww.securityweek.comOct 21, 2022, 10:28 AMCisco’s Talos security researchers warn of a newly identified attack framework and its associated remote access trojan (RAT) targeting Windows, Linux, and macOS systems.
newswww.securityweek.comOct 14, 2022, 12:57 PMResearchers have discovered a new attack framework of Chinese origin that they believe is being used in the wild. The framework is made up of a command-and-control (C2) backend dubbed Alchimist and an accompanying customizable remote access Trojan (RAT) for Windows and Linux machines. The framework can also be used to generate PowerShell-based attack shellcode […]
newswww.csoonline.comOct 13, 2022, 5:52 PM- The discovery of Alchimist C2 tool, revealed a new attack framework to target Windows, macOS, and Linux systemsSecurity Affairs
Experts discovered a new attack framework, including a C2 tool dubbed Alchimist, used in attacks against Windows, macOS, and Linux systems. Researchers from Cisco Talos discovered a new, previously undocumented attack framework that included a C2 dubbed Alchimist. The framework is likely being used in attacks aimed at Windows, macOS, and Linux systems. The experts […]
newssecurityaffairs.comOct 13, 2022, 2:59 PM Security researchers with AT&T Alien Labs are warning of a new piece of malware that can take full control of infected Linux systems, including Internet of Things (IoT) devices.
newswww.securityweek.comSep 8, 2022, 6:01 PM- Experts spotted a new stealthy Linux malware dubbed ShikitegaSecurity Affairs
A new Linux malware dubbed Shikitega leverages a multi-stage infection chain to target endpoints and IoT devices. Researchers from AT&T Alien Labs discovered a new piece of stealthy Linux malware, dubbed Shikitega, that targets endpoints and IoT devices. The malware stands out for its multistage infection chain, threat actors use it to gain full control of the system […]
newssecurityaffairs.comSep 7, 2022, 4:38 PM - Evasive Shikitega Linux malware drops Monero cryptominerMalwarebytes Labs
Researchers from the AT&T Alien Labs Resarch have discovered a new and stealthy Linux malware it’s dubbed Shikitega. Once it’s on…
newswww.malwarebytes.comSep 6, 2022, 5:00 PM The US Cybersecurity and Infrastructure Security Agency (CISA) says a Linux vulnerability tracked as CVE-2021-4034 and PwnKit has been exploited in attacks.
newswww.securityweek.comJun 28, 2022, 4:43 PM- Week in review: PolKit vulnerability, fake tax apps pushing malware, EU’s bug bounty for open sourceHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: PolKit vulnerability can give attackers root on many Linux distros (CVE-2021-4034) A memory corruption vulnerability (CVE-2021-4034) in PolKit, a component used in major Linux distributions and some Unix-like operating systems, can be easily exploited by local unprivileged users to gain full root privileges. DazzleSpy: macOS backdoor delivered through watering hole attacks In late 2021, a never before seen macOS backdoor was … More →
newswww.helpnetsecurity.comJan 30, 2022, 9:00 AM Security researchers have found a privilege escalation vulnerability in pkexec, a tool that’s present by default on many Linux installations. The flaw, called PwnKit, could allow attackers to easily gain root privileges on systems if they have access to a regular user without administrative privileges. Researchers from security firm Qualys who discovered and reported the […]
newswww.csoonline.comJan 26, 2022, 2:50 PMQualys security researchers warn of an easily exploitable privilege escalation vulnerability in polkit’s pkexec, a SUID-root program found in all Linux distributions.
newswww.securityweek.comJan 26, 2022, 12:31 PMA flaw in Polkit’s pkexec component, tracked as CVE-2021-4034 (PwnKit) can be exploited to gain full root privileges on major Linux distros. An attacker can exploit a vulnerability in Polkit’s pkexec component, tracked as CVE-2021-4034, that affects all major Linux distributions to gain full root privileges on the system. The good news is that this […]
newssecurityaffairs.comJan 26, 2022, 11:12 AMA memory corruption vulnerability (CVE-2021-4034) in PolKit, a component used in major Linux distributions and some Unix-like operating systems, can be easily exploited by local unprivileged users to gain full root privileges. While the vulnerability is not exploitable remotely and doesn’t, in itself, allow arbitrary code execution, it can be used by attackers that have already gained a foothold on a vulnerable host to escalate their privileges and achieve that capability. About the vulnerability (CVE-2021-4034) … More →
newswww.helpnetsecurity.comJan 26, 2022, 9:44 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
4 repository references · best confidence 0.99 · max 2 stars
- hackingyseguridad/rootHigh confidencegithubRepository topic discovery2 starsDiscovered Jul 12, 2026, 10:50 PM
- ropydev/CVE-2021-4034-PwnKitHigh confidencegithubDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 5:43 AM
- FR4NC0X/pwnkit-helperHigh confidencegitlabDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 6:51 PM
- mac3d0/CVE-2021-4034-pwnkitHigh confidencegithubDiscovery source unavailable0 starsDiscovered Jul 10, 2026, 8:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-44142CVSS 8.8 · High
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP filese…
- CVE-2019-11043CVSS 8.7 · High
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buf…
- CVE-2020-25717CVSS 8.1 · High
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
- CVE-2016-2124CVSS 5.9 · Medium
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentic…
- CVE-2019-6454CVSS 5.5 · Medium
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the obje…
- CVE-2018-16866CVSS 3.3 · Low
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process…