Junglewise Threat Intelligence

CVE-2021-3560: Red Hat Polkit Incorrect Authorization Vulnerability

CVE-2021-3560 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-05-12

Technologies: Polkit Project Polkit, Debian Linux, Red Hat OpenShift Container Platform, Red Hat Enterprise Linux. Vendors: Debian, Red Hat, Canonical, Red Hat.

Executive brief

Polkit (formerly PolicyKit) contains a vulnerability where it can be tricked into bypassing credential checks for D-Bus requests. This allows an unprivileged local attacker to escalate privileges to root, potentially creating new administrator accounts.

Affected products

  • Polkit Project Polkit up to (excluding) 0.119
  • Red Hat Enterprise Linux 7.0, 8.0
  • Red Hat OpenShift Container Platform 4.7
  • Red Hat Virtualization 4.0
  • Canonical Ubuntu Linux 20.04
  • Debian Debian Linux 11.0

Timeline

  • 2021-06-10: disclosed: Public disclosure of the vulnerability via GitHub blog.
  • 2022-02-16: other: NVD Published Date.
  • 2023-05-12: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats