Executive brief
Polkit (formerly PolicyKit) contains a vulnerability where it can be tricked into bypassing credential checks for D-Bus requests. This allows an unprivileged local attacker to escalate privileges to root, potentially creating new administrator accounts.
Affected products
- Polkit Project Polkit up to (excluding) 0.119
- Red Hat Enterprise Linux 7.0, 8.0
- Red Hat OpenShift Container Platform 4.7
- Red Hat Virtualization 4.0
- Canonical Ubuntu Linux 20.04
- Debian Debian Linux 11.0
Timeline
- 2021-06-10: disclosed: Public disclosure of the vulnerability via GitHub blog.
- 2022-02-16: other: NVD Published Date.
- 2023-05-12: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.