ZeroHour

CVE-2021-3560

KEV PoC mass1

Incorrect Authorization in Red Hat Polkit Allows Local Privilege Escalation

CISA: Red Hat Polkit Incorrect Authorization Vulnerability

CVSS 3.1
7.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

Red Hat's Polkit (PolicyKit), the component that enforces authorization policy for privileged D-Bus requests, fails to correctly verify credentials for D-Bus requests: when the calling client drops its connection before the authorization check completes, Polkit treats the request as if it came from a privileged process. A local, unprivileged user can trigger this by initiating a D-Bus call to a system service and terminating the connection at the right moment, making the race straightforward to hit with repeated attempts. A successful exploit bypasses the credential check and escalates the attacker's privileges to root on the affected host. Any Red Hat system shipping the vulnerable Polkit build is affected, and no public proof-of-concept is documented. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2023-05-12), which indicates known exploitation in the wild, though ransomware use is unknown.

What to do: Apply updated Polkit packages per Red Hat's advisory instructions on all affected systems, and verify the running Polkit version matches the vendor's fixed release. Because the flaw is CISA KEV-listed with a 22.2% EPSS, prioritize patching on multi-user and internet-exposed hosts; where patching is delayed, restrict local shell access to untrusted users, since the flaw requires local access to trigger.

Affected
Red Hat Polkit (PolicyKit)
Estimated exposure
massmillions of systems (Polkit ships by default on Red Hat Enterprise Linux and Fedora installs) — Polkit is part of the default package set on essentially every Red Hat Enterprise Linux and Fedora installation, and the cumulative installed base of these platforms is measured in the millions of systems.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CISA Known Exploited Vulnerability
Affected
Red Hat Polkit
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
polkit projectdebiancanonicalredhat
Products
polkit, debian linux, ubuntu linux, virtualization, virtualization host, openshift container platform
Weakness
CWE-863, CWE-754
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news