LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-3560: Red Hat Polkit Incorrect Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 12, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 2, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-3560 to its Known Exploited Vulnerabilities catalog on May 12, 2023, with a federal patch deadline of Jun 2, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.

CVE-2021-3560 is an incorrect authorization flaw in Red Hat Polkit that lets an attacker bypass credential checks on certain D-Bus requests and escalate privileges. Polkit is a common authorization service on Linux systems that decides whether a process may perform privileged actions; when those checks can be skipped, a low-privileged local user can gain higher rights. Because Polkit is widely present on enterprise Linux distributions, the issue matters for any environment that relies on it for access control.

Public detail is limited to the CISA description of the weakness and the required action to apply vendor updates. Confirm exact package versions, fixed releases, and any additional configuration notes against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-863 (Incorrect Authorization). Polkit evaluates authorization for D-Bus method calls that request privileged operations. In the affected implementation, the credential-checking path can be bypassed, so the service may grant the requested privilege without properly verifying the caller’s identity or rights. An attacker who already has a local foothold can craft or sequence D-Bus requests that trigger this path, obtaining elevated privileges on the host. No remote network vector is described; the abuse model is local privilege escalation. Specific request formats or timing details are not provided in the available facts and must be confirmed against the vendor advisory if needed for detection rules.

Am I affected? How to find it in your systems

Polkit (often packaged as polkit or policykit) typically runs on Red Hat Enterprise Linux and related distributions, as well as other Linux systems that use the same authorization framework. It is commonly present on servers, workstations, and container hosts that perform privileged operations via D-Bus.

Because exact vulnerable version ranges are not supplied here, treat any unpatched Polkit installation as potentially affected until the advisory confirms otherwise.

How to remediate

Apply the vendor-supplied update for Polkit as directed by the advisory; CISA’s required action is simply to apply updates per vendor instructions. After patching, restart any services that depend on Polkit if the advisory recommends it, then re-verify the package version.

If you can't patch immediately

Until the update can be installed, reduce exposure with compensating controls that limit the attacker’s ability to reach or abuse the flawed authorization path.

These measures only lower risk; they do not eliminate the underlying incorrect-authorization condition.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. If privilege escalation succeeded on a host that stores or processes sensitive data, treat the system as potentially compromised, preserve forensic evidence, and follow your incident-response plan. You can run a free exposure scan of your email address to check whether it appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRed Hat · Polkit
WeaknessCWE-863
Added to CISA KEVMay 12, 2023
Federal patch deadlineJun 2, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities