A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
CVE-2021-4034
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 7.8
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS
- 99.9%
- KEV
- ⚠ Exploited
Published
January 28, 2022
Last Modified
November 6, 2025
Advisory Details (8)
Auto-updated Jun 4, 2026CVE-2021-4034 PolicyKit privilege escalation vulnerability in StarWind products
https://www.starwindsoftware.com/security/sw-20220818-0001/PwnKit Linux vulnerability Jan-2022: Local Privilege Escalation Vulner | SecPod
https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/pkexec: local privilege escalation (CVE-2021-4034) (a2bf5c9c) · Commits · polkit / polkit · GitLab
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded6832025869 – (CVE-2021-4034) CVE-2021-4034 polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
Affected: Red Hat Enterprise Linux 8.2 Extended Update Support
https://bugzilla.redhat.com/show_bug.cgi?id=2025869RHSB-2022-001 Polkit Privilege Escalation - (CVE-2021-4034) | Red Hat Customer Portal
Affected: Red Hat Enterprise Linux 6
https://access.redhat.com/security/vulnerabilities/RHSB-2022-001Vendor Advisories for CVE-2021-4034(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(14)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | libpolkit-gobject-1-0 (0.105-31ubuntu0.1) @ impish | 2026-07-22 | ubuntu |
| ubuntu | policykit-1-doc (0.105-14.1ubuntu0.5+esm1) @ xenial | 2026-07-22 | ubuntu |
| redhat | redhat-virtualization-host-0:4.4.10-202202081536_8.5 | 2022-02-15 | redhat |
| redhat | redhat-virtualization-host-0:4.3.21-20220126.0.el7_9 | 2022-02-07 | redhat |
| redhat | polkit-0:0.112-12.el7_3.1 | 2022-01-25 | redhat |
| redhat | polkit-0:0.112-12.el7_4.2 | 2022-01-25 | redhat |
| redhat | polkit-0:0.112-18.el7_6.3 | 2022-01-25 | redhat |
| redhat | polkit-0:0.112-22.el7_7.2 | 2022-01-25 | redhat |
| redhat | polkit-0:0.115-11.el8_2.2 | 2022-01-25 | redhat |
| redhat | polkit-0:0.115-11.el8_4.2 | 2022-01-25 | redhat |
| redhat | polkit-0:0.112-26.el7_9.1 | 2022-01-25 | redhat |
| redhat | polkit-0:0.96-11.el6_10.2 | 2022-01-25 | redhat |
| redhat | polkit-0:0.115-13.el8_5.1 | 2022-01-25 | redhat |
| redhat | polkit-0:0.115-9.el8_1.2 | 2022-01-25 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(14)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Microsoft MSRCCVE-2021-40342022-01-30
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
- Red HatRHSA-2022:0265IMPORTANT2022-01-25
RHSA-2022:0265 — Important
- Red HatRHSA-2022:0266IMPORTANT2022-01-25
RHSA-2022:0266 — Important
- Red HatRHSA-2022:0267IMPORTANT2022-01-25
RHSA-2022:0267 — Important
- Red HatRHSA-2022:0268IMPORTANT2022-01-25
RHSA-2022:0268 — Important
- Red HatRHSA-2022:0269IMPORTANT2022-01-25
RHSA-2022:0269 — Important
- Red HatRHSA-2022:0270IMPORTANT2022-01-25
RHSA-2022:0270 — Important
- Red HatRHSA-2022:0271IMPORTANT2022-01-25
RHSA-2022:0271 — Important
- Red HatRHSA-2022:0272IMPORTANT2022-01-25
RHSA-2022:0272 — Important
- Red HatRHSA-2022:0273IMPORTANT2022-01-25
RHSA-2022:0273 — Important
- Red HatRHSA-2022:0443IMPORTANT2022-01-25
RHSA-2022:0443 — Important
- Red HatRHSA-2022:0540IMPORTANT2022-01-25
RHSA-2022:0540 — Important
- UbuntuUSN-5252-1HIGH
PolicyKit vulnerability
- UbuntuUSN-5252-2HIGH
PolicyKit vulnerability
Data Freshness Timeline
(refreshed 62× in last 7d / 340× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 663 total refreshes for this CVE.
- 2026-07-23 14:16 UTCEPSS rescore
- 2026-07-23 02:04 UTCEG score recompute
- 2026-07-22 22:50 UTCEG score recompute
- 2026-07-22 22:50 UTCVendor advisory
- 2026-07-22 22:50 UTCGHSA enrichment
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 18:33 UTCVendor advisory
- 2026-07-22 18:33 UTCGHSA enrichment
- 2026-07-22 14:18 UTCVendor advisory
- 2026-07-22 14:17 UTCGHSA enrichment
- 2026-07-22 10:01 UTCVendor advisory
- 2026-07-22 10:01 UTCGHSA enrichment
- 2026-07-22 05:45 UTCVendor advisory
- 2026-07-22 05:45 UTCGHSA enrichment
- 2026-07-22 01:29 UTCVendor advisory
- 2026-07-22 01:29 UTCGHSA enrichment
- 2026-07-21 21:12 UTCVendor advisory
- 2026-07-21 21:12 UTCGHSA enrichment
- 2026-07-21 16:54 UTCEG score recompute
- 2026-07-21 16:54 UTCVendor advisory
- 2026-07-21 16:54 UTCGHSA enrichment
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 12:38 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-21 12:38 UTCGHSA enrichment
- 2026-07-21 08:22 UTCVendor advisory
- 2026-07-21 08:22 UTCGHSA enrichment
- 2026-07-21 04:06 UTCVendor advisory
- 2026-07-21 04:06 UTCGHSA enrichment
- 2026-07-20 23:50 UTCVendor advisory
- 2026-07-20 23:50 UTCGHSA enrichment
- 2026-07-20 19:34 UTCEG score recompute
- 2026-07-20 19:34 UTCVendor advisory
- 2026-07-20 19:34 UTCGHSA enrichment
- 2026-07-20 17:05 UTCEPSS rescore
- 2026-07-20 15:19 UTCVendor advisory
- 2026-07-20 15:18 UTCGHSA enrichment
- 2026-07-20 11:02 UTCVendor advisory
- 2026-07-20 11:02 UTCGHSA enrichment
- 2026-07-20 06:45 UTCVendor advisory
- 2026-07-20 06:45 UTCGHSA enrichment
- 2026-07-20 02:11 UTCVendor advisory
- 2026-07-20 02:11 UTCGHSA enrichment
- 2026-07-19 21:55 UTCVendor advisory
- 2026-07-19 21:55 UTCGHSA enrichment
- 2026-07-19 17:39 UTCVendor advisory
- 2026-07-19 17:39 UTCGHSA enrichment
- 2026-07-19 13:23 UTCVendor advisory
- 2026-07-19 13:23 UTCGHSA enrichment
- 2026-07-19 09:08 UTCVendor advisory
- 2026-07-19 09:08 UTCGHSA enrichment
- 2026-07-19 04:52 UTCVendor advisory
- 2026-07-19 04:52 UTCGHSA enrichment
- 2026-07-19 00:36 UTCVendor advisory
- 2026-07-19 00:36 UTCGHSA enrichment
- 2026-07-18 20:19 UTCVendor advisory
- 2026-07-18 20:19 UTCGHSA enrichment
- 2026-07-18 16:03 UTCVendor advisory
- 2026-07-18 16:03 UTCGHSA enrichment
- 2026-07-18 11:48 UTCVendor advisory
- 2026-07-18 11:48 UTCGHSA enrichment
- 2026-07-18 07:32 UTCVendor advisory
- 2026-07-18 07:32 UTCGHSA enrichment
- 2026-07-18 03:16 UTCVendor advisory
- 2026-07-18 03:16 UTCGHSA enrichment
- 2026-07-17 22:59 UTCVendor advisory
- 2026-07-17 22:59 UTCGHSA enrichment
- 2026-07-17 18:43 UTCVendor advisory
- 2026-07-17 18:43 UTCGHSA enrichment
- 2026-07-17 14:27 UTCVendor advisory
- 2026-07-17 14:27 UTCGHSA enrichment
- 2026-07-17 10:11 UTCEG score recompute
- 2026-07-17 10:11 UTCVendor advisory
- 2026-07-17 10:11 UTCGHSA enrichment
- 2026-07-17 05:55 UTCVendor advisory
- 2026-07-17 05:55 UTCGHSA enrichment
- 2026-07-17 01:39 UTCVendor advisory
- 2026-07-17 01:38 UTCGHSA enrichment
- 2026-07-16 21:22 UTCVendor advisory
- 2026-07-16 21:22 UTCGHSA enrichment
- 2026-07-16 17:06 UTCVendor advisory
- 2026-07-16 17:05 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 12:49 UTCVendor advisory
- 2026-07-16 12:49 UTCGHSA enrichment
- 2026-07-16 08:33 UTCVendor advisory
- 2026-07-16 08:33 UTCGHSA enrichment
- 2026-07-16 04:17 UTCVendor advisory
- 2026-07-16 04:17 UTCGHSA enrichment
- 2026-07-16 00:01 UTCVendor advisory
- 2026-07-16 00:01 UTCGHSA enrichment
- 2026-07-15 19:45 UTCVendor advisory
- 2026-07-15 19:45 UTCGHSA enrichment
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:29 UTCVendor advisory
- 2026-07-15 15:29 UTCGHSA enrichment
- 2026-07-15 15:04 UTCCISA KEV update
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCwudicainiao/cve-2021-4034First seen May 21, 2022
CVE-2021-4034 for single commcand
Open source ↗ - GitHub PoCrvizx/CVE-2021-4034First seen Feb 4, 2022
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python
Open source ↗ - GitHub PoCrvzsec/CVE-2021-4034First seen Feb 4, 2022
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python
Open source ↗ - Exploit-DBEDB-50689First seen Jan 27, 2022
PolicyKit-1 0.105-31 - Privilege Escalation
Open source ↗ - GitHub PoCPwnFunction/CVE-2021-4034First seen Jan 27, 2022
Proof of concept for pwnkit vulnerability
Open source ↗ - GitHub PoCtahaafarooq/poppyFirst seen Jan 27, 2022
CVE-2021-4034 PoC , polkit < 0.131
Open source ↗ - Open source ↗GitHub PoCY3A/CVE-2021-4034First seen Jan 26, 2022
- GitHub PoCly4k/PwnKitFirst seen Jan 26, 2022
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
Open source ↗ - GitHub PoCarthepsy/CVE-2021-4034First seen Jan 26, 2022
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
Open source ↗ - Open source ↗GitHub PoCdadvlingd/CVE-2021-4034First seen Jan 26, 2022
Frequently asked(6)
What is CVE-2021-4034?
When was CVE-2021-4034 disclosed?
Is CVE-2021-4034 actively exploited?
What is the CVSS score of CVE-2021-4034?
Which products are affected by CVE-2021-4034?
How do I remediate CVE-2021-4034?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2021-4034
Is Your Infrastructure Affected by CVE-2021-4034?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.