LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-4034: Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 27, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-4034 to its Known Exploited Vulnerabilities catalog on Jun 27, 2022, with a federal patch deadline of Jul 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

CVE-2021-4034 is an out-of-bounds read and write vulnerability in the Red Hat polkit pkexec utility. It allows a local attacker to escalate privileges to administrative rights. This matters because polkit is widely used on Linux systems to control privileged operations; successful abuse can give an unprivileged user full control of the host.

Defenders should treat this as a high-priority local privilege-escalation issue. Confirm exact affected packages and fixed versions against the vendor advisory before acting.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In the pkexec utility, improper handling of certain inputs leads to memory accesses outside the intended bounds. An attacker who can already execute code as a low-privileged user can trigger the flaw to corrupt memory in a way that elevates their privileges to administrative (root) level.

Public detail on the precise trigger is limited to the CISA description: the Red Hat polkit pkexec utility contains the out-of-bounds read and write that enables this escalation. No further exploit mechanics are provided here; teams should rely on the vendor advisory and their own testing rather than unconfirmed public proofs-of-concept.

Am I affected? How to find it in your systems

Polkit (and its pkexec helper) is commonly installed by default on Red Hat Enterprise Linux and many derivative or related Linux distributions. It runs on servers, workstations, and containers that need policy-based privilege management.

How to remediate

Patch first. Apply the updates supplied by the vendor exactly as described in the advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk. Implement them only as a bridge until the vendor update can be applied.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities frequently serve as a stepping stone to broader compromise, data theft, or ransomware deployment. Known ransomware use of this specific CVE is not documented, yet any successful escalation should be treated as a potential breach precursor. Investigate affected hosts for persistence, lateral movement, and data access. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRed Hat · Polkit
WeaknessCWE-787
Added to CISA KEVJun 27, 2022
Federal patch deadlineJul 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities