CVE-2021-3560General(canonical / debian_linux)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for canonical debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-06-02. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-863CWE-754

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • enterprise_linux
  • openshift_container_platform
  • polkit

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 6d ago at 1 mentions (2026-01-30); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Products
debian_linuxenterprise_linuxopenshift_container_platformpolkitubuntu_linuxvirtualizationvirtualization_host

6 versions affected across 7 products

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-01-30: 1Mentions · 2026-03-13: 1Mentions · 2026-03-28: 1Mentions · 2026-04-01: 1Mentions · 2026-04-21: 1Mentions · 2026-08-20: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-08-20: 1Active Exploitation · 2026-09-24: 1Technical Details · 2026-08-20: 1Technical Details · 2026-09-24: 101-3003-1303-2804-0104-2108-2009-24
Signal classification4 categories
General
457.1%
PoC
114.3%
Disclosure
114.3%
Active Exploitation
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-01-301
General1
2026-03-131
General1
2026-03-281
General1
2026-04-011
General1
2026-04-211
PoC1
2026-08-201
Disclosure1
2026-09-241
Active Exploitation1
Full discourse7 posts
  • Jethro Beekman@JethroGB
    Active Exploitation

    @filpizlo Ok, how about CVE-2021-3560 (polkit, in CISA KEV)? A fn returned TRUE on err with uid still 0-initialized, so any local user gets root. Every mem access is valid; behavior in Fil-C would be identical. In Rust, a Result would've been used which can't be Ok and Err at the same time

    Post summary

    The tweet highlights CVE-2021-3560 (polkit) as a known actively exploited vulnerability in CISA KEV, allowing local privilege escalation to root due to a logic flaw. It provides technical details about the vulnerability's mechanics and compares language-specific behavior in handling errors.

    0000031
    455 followersView on X
  • Redwan Ahmed 🇧🇩 🇪🇭@r3dw4n48m3d
    Disclosure

    Polkit: CVE-2021-3560 https://github.blog/security/vulnerability-research/privilege-escalation-polkit-root-on-linux-with-bug/

    Post summary

    GitHub researchers disclosed a privilege‑escalation vulnerability in Polkit (CVE‑2021‑3560) and linked to their blog post; no details on active exploitation, fixes, or false positives were provided.

    0000034
    31 followersView on X
  • Jayesh Verma@JayeshV88153533
    PoC

    I just completed Polkit: CVE-2021-3560 room on TryHackMe! Walkthrough room for CVE-2021-3560 https://tryhackme.com/room/polkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=684d724b80fe1af75347f3e4 #tryhackme via @tryhackme

    Post summary

    User shares a TryHackMe walkthrough for Polkit CVE‑2021‑3560, providing PoC steps via a linked room, with no known active exploitation, patch, or false‑positive claim.

    0000019
    16 followersView on X
  • Sun4lower@LittleSun4lower
    General

    I just completed Polkit: CVE-2021-3560 room on TryHackMe! Walkthrough room for CVE-2021-3560 https://tryhackme.com/room/polkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #consistency #LearningJourney

    Post summary

    The tweet announces the completion of a TryHackMe walkthrough for Polkit CVE-2021-3560 and provides a link to the room, but offers no technical details, exploits, or mitigation information.

    0000043
    5 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Polkit: CVE-2021-3560 room on TryHackMe! Walkthrough room for CVE-2021-3560 https://tryhackme.com/room/polkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet shares a link to a TryHackMe walkthrough for Polkit CVE-2021-3560, offering a tutorial without detailed vulnerability or exploit information.

    0000029
  • PulseEinher@PulseEinher
    General

    Day 60/100 ✔ LeetCode: Remove Element https://leetcode.com/problems/remove-element/description/ ✔ TryHackMe: Polkit: CVE-2021-3560 https://tryhackme.com/room/polkit ✔ Medium: Tokyo Ghoul CTF – Walkthrough https://medium.com/@pulse-einher/try-hack-me-tokyo-ghoul-ctf-walkthrough-cceefe32a260 Continuing tomorrow. https://t.co/h4hEZVcOje

    Post summary

    The post simply lists a training room and a CTF walkthrough with no additional details on exploitation or mitigation.

    0000042
  • Maekawa/DXevj7ck@DXevj7ck
    General

    I just completed Polkit: CVE-2021-3560 room on TryHackMe! Walkthrough room for CVE-2021-3560 https://tryhackme.com/room/polkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=6427f6e9b2b8600043d36908 #tryhackme @tryhackme

    Post summary

    The user reports completing a TryHackMe walkthrough for CVE-2021-3560, with no other technical or exploit-related details provided.

    0000077
    2 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux20.04--
OSdebiandebian_linux11.0--
Apppolkit_projectpolkit---
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
Appredhatopenshift_container_platform4.7--
Appredhatvirtualization4.0--
Appredhatvirtualization_host4.0--

Explore more