CVE-2021-4034
CWE-787
91.7
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Source: NVD
Signals
- CVSS
- 7.8
- High · v3.1
- EPSS
- 94.34%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Jun 2022
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-787
- CWE-787, CWE-125
- Published
- 28 Jan 2022
- Last modified 15 Aug 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2021-4034Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time