What it is
CVE-2021-4034 is a vulnerability affecting freedesktop.org polkit. A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow...
Vulnerability report
polkit Privilege Escalation
freedesktop.org / polkit · all
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2021-4034 is a vulnerability affecting freedesktop.org polkit. A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
freedesktop.org / polkit all.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands.
An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
Independent exploitation attestation added to the KEV Intelligence record.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-06-27 00:00 UTC |
| CVE | 2026-08-15 04:10 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Metasploit template detected 28 Apr 2025.
View Metasploit template (opens in new tab)No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2021_4034_pwnkit_lpe_pkexec.rb | 28 Apr 2025 |
Risk and context
CVSS v3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
94.9%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2022-01-28 15:13:28 UTC · 97 stars · AI assessment 90%
CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation
github · Created 2022-01-28 02:54:38 UTC · 79 stars · AI assessment 90%
CVE-2021-4034简单优化,以应对没有安装gcc和make的目标环境
github · Created 2022-01-27 17:43:24 UTC · 25 stars · AI assessment 85%
Pre-compiled builds for CVE-2021-4034
github · Created 2022-01-27 14:43:57 UTC · 344 stars · AI assessment 90%
Proof of concept for pwnkit vulnerability
github · Created 2022-01-26 17:53:16 UTC · 165 stars · AI assessment 90%
Python exploit code for CVE-2021-4034 (pwnkit)
github · Created 2022-01-26 07:19:21 UTC · 45 stars · AI assessment 90%
polkit pkexec Local Privilege Vulnerability to Add custom commands
github · Created 2022-01-26 03:33:47 UTC · 93 stars · AI assessment 90%
Exploit for CVE-2021-4034
github · Created 2022-01-26 02:02:25 UTC · 62 stars · AI assessment 90%
PoC for CVE-2021-4034
github · Created 2022-01-26 00:56:36 UTC · 1078 stars · AI assessment 90%
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
github · Created 2022-01-25 23:51:37 UTC · 1990 stars · AI assessment 90%
CVE-2021-4034 1day
github · Created 2022-01-25 23:11:30 UTC · 72 stars · AI assessment 90%
Local Privilege Escalation in polkit's pkexec
Timeline
Exploitation attested by an external source
Exploit module available
Listed in the CISA Known Exploited Vulnerabilities catalog
Vulnerability disclosed publicly
Public proof-of-concept code published
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2021-4034
Free JSON includes basic KEV fields{
"cve_id": "CVE-2021-4034",
"confidence": "Confirmed",
"cvss_score": 7.8,
"cvss_estimated": false,
"epss_score": 0.94921,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.