CVE-2021-4034PoC(canonical / command_center)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for canonical command_center systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-07-18. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-787CWE-125

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • command_center
  • enterprise_linux
  • enterprise_linux_desktop
  • enterprise_linux_eus

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 14 mentions across 13 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Technical details provided in 5 signals
  • General: 6 classified signals
  • Peaked 2d ago at 2 mentions (2026-09-10); latest day: 1
  • 14 total mentions across 13 days

Affected systems

Products
command_centerenterprise_linuxenterprise_linux_desktopenterprise_linux_eusenterprise_linux_for_ibm_z_systemsenterprise_linux_for_ibm_z_systems_eusenterprise_linux_for_power_big_endianenterprise_linux_for_power_little_endianenterprise_linux_for_power_little_endian_eusenterprise_linux_for_scientific_computing

25 versions affected across 31 products

Deep dive

Activity timeline14 mentions / 13d
01122Mentions · 2026-01-29: 1Mentions · 2026-03-03: 1Mentions · 2026-03-12: 1Mentions · 2026-03-27: 1Mentions · 2026-04-18: 1Mentions · 2026-05-03: 1Mentions · 2026-05-11: 1Mentions · 2026-06-26: 1Mentions · 2026-08-07: 1Mentions · 2026-08-15: 1Mentions · 2026-09-10: 2Mentions · 2026-09-14: 1Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-05-03: 1PoC Mentioned / Linked · 2026-08-07: 1PoC Mentioned / Linked · 2026-09-10: 2Exploit Tool / Code · 2026-08-07: 1Exploit Tool / Code · 2026-09-25: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-09-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-08-07: 1Technical Details · 2026-09-10: 2Technical Details · 2026-09-25: 101-2903-0303-1203-2704-1805-0305-1106-2608-0708-1509-1009-1409-25
Signal classification3 categories
PoC
642.9%
General
642.9%
Active Exploitation
214.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-01-291
PoC1
2026-03-031
PoC1
2026-03-121
General1
2026-03-271
PoC1
2026-04-181
General1
2026-05-031
PoC1
2026-05-111
General1
2026-06-261
General1
2026-08-071
PoC1
2026-08-151
Active Exploitation1
2026-09-102
General1PoC1
2026-09-141
General1
2026-09-251
Active Exploitation1
Full discourse14 posts
  • 0x0さん@LxlxIxlxlxL
    PoC

    pkexec ships SUID-root on every major Linux distro. it had a local root exploit in its very first commit, May 2009, hidden for 12 years. CVE-2021-4034, "PwnKit". the bug isn't a clever overflow. it's what happens when you assume argc is never 0. execve lets you run a program with an empty argument list: argv = {NULL}, argc = 0. here's main() processing the args: 534 for (n = 1; n < (guint) argc; n++) if argc is 0 the loop never runs and n stays 1. a few lines down: 610 path = g_strdup (argv[n]); 639 argv[n] = path = s; it reads and writes argv[1]. but argc was 0, so argv[1] doesn't exist. the kernel lays argv and envp back-to-back on the stack, so argv[1] is actually envp[0], your first environment variable. so pkexec reads a program name from your env, resolves it via PATH, and writes the result back over envp[0]. that's an arbitrary write into the environment of a SUID-root process, the exact thing http://ld.so strips for SUID binaries. re-introduce GCONV_PATH, point it at your own .so, trigger an error message, and pkexec loads your library as root. no ASLR bypass, no ROP, no arch-specific offsets. instant, reliable, works even with the polkit daemon dead. https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt

    Post summary

    The passage details how CVE‑2021‑4034 (PwnKit) can be leveraged by manipulating environment variables, provides PoC logic, and links to an external write‑up, but does not report live exploitation or patches.

    015089599.3K
    923 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    10件の脆弱性でランサムウェアによる悪用が確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。対象は以下。 - CVE-2025-60710 (Windows) - CVE-2020-29574 (CyberoamOS) - CVE-2020-0618 (SQL Server) - CVE-2021-4034 (polkit) - CVE-2016-0189 (IE) - CVE-2022-21882 (Windows) - CVE-2019-5591 (FortiOS) - CVE-2019-0803 (Windows) - CVE-2018-0802 (Office) - CVE-2020-0968 (IE)

    Post summary

    The update reports that ten known vulnerabilities are being actively exploited by ransomware, as confirmed by CISA.

    01121102.7K
    7.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Operation Master exposed: a single Brazilian 🇧🇷 threat actor ran a full intrusion-to-fraud pipeline, exploiting CVE-2026-0257 across 7 GlobalProtect gateways in four countries, stealing 600+ companies' data, then weaponizing it inside an automated multi-tenant invoice fraud platform that generated 2.4M+ messages and R$150.4M in attempted PIX fraud. - CVE-2026-0257 (GlobalProtect authentication bypass) was the primary at-scale access vector. The actor forged auth cookies from target certificate context and fed candidates through a 30-worker automated exploit loop driven by continuous masscan output across 277.5M scanned hosts. The same CVE is being exploited separately by ransomware actors including Qilin, making it a high-priority patch target. Beyond VPN access, parallel campaigns hit SQLi targets via sqlmap and xp_cmdshell chains to pivot from database access to host execution, with DNS subdomain tunneling (470,268 queries from a single compromised host, structured as task.row.chunk.base64.x.random.victim-hostname) as the primary exfil rail, and rclone syncing to MEGA as a redundant second channel. Staged webshells (beacon.dll, wmsvc.dll, gopher_new.exe) and AdaptixC2 on 91.92.241[.]187 (ports 8443/4444/4321) provided C2 over HTTP and raw TCP. Additional techniques: SAM/SYSTEM/SECURITY hive theft (T1003.002), ntds.dit recovery (T1003.003), GodPotato token impersonation, PwnKit (CVE-2021-4034), CVE-2024-1086, and CVE-2023-7028 (CVSS 10.0 GitLab dual-email reset) hardcoding cyberkill2025[@]http://gmail.com as the attacker-controlled recovery address. - The fraud monetization layer is a Node.js multi-tenant "master-panel" at /opt/master-panel/, running under PM2, backed by PostgreSQL and SQLite, and exposed externally on yzs[.]fi. Lookalike domains igreenfaturas[.]to, wattiofaturas[.]com, and nuvfaturas[.]com hosted per-victim invoice pages with URL parameters embedding the victim's real name, due date, consumption, and billing amount pulled from stolen utility databases. Email delivery routed through 12 hijacked M365 mailboxes (retail, healthcare, education) to inherit sender reputation. SMS ran across 8 SMPP gateways. PIX payments routed through a serverless Vercel proxy at pix-proxy-sable.vercel[.]app. The lead source was 1.8M records scraped via a passwordless JWT flaw in iGreen Energia's API. The fraud engine logged 622,666 personalized links, 317,696 click events, and R$38.9M in fraudulent invoices opened by victims. - Attribution converges on forum persona masterblack and primary email cyberkill2025[@]http://gmail.com, which appears across: 34 fraud panel lead test records, the GitLab CVE-2023-7028 exploit hardcoding, OSINT API registrations (Shodan, VirusTotal, SecurityTrails, WPScan, AlienVault OTX), a recovered pentest report listing the operator, and a leaked hacker forum database record directly linking the email to the masterblack account that sold stolen iGreen and Wattio data weeks before the fraud campaigns began. The two-stage strategy, sell the data first, then phish the same victims with their own billing records, is confirmed by the 9 to 14 week gap between forum sale listings and bulk tenant seeding. The operator's AI agent workspace (36+ offensive subagents, ~45 persistent memory files) was exposed via a misconfigured cloud backup reachable from the first exploitation server at 85.120.216[.]8. - Key detection opportunities from the article: sqlservr.exe spawning cmd.exe or PowerShell is a high-fidelity signal for the xp_cmdshell chain. High-entropy DNS queries from database service identities indicate active tunneling. rclone or unauthorized cloud-sync binaries on servers warrant immediate investigation. OAuth device-code grants without corresponding enrollment events indicate T1598 phishing. Unauthorized reads of SAM, SYSTEM, SECURITY hives or ntds.dit by service accounts are critical alerts. For the fraud infrastructure specifically, URL parameters matching the schema ?ref=, venc=, v=, v0=, kwh= on lookalike utility domains are a structural indicator of the invoice fraud platform's output. Full IOC table (IPs, domains, SHA-256 hashes for all beacon and agent variants, qTox IDs) and the complete MITRE ATT&CK mapping are in the SOCRadar report. Prioritize hunting for AdaptixC2 gopher agent artifacts (gopher_new.exe SHA-256 54caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37b, beacon.dll SHA-256 d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217c) and block the four operation server IPs: 85.120.216[.]8, 91.92.241[.]187, 91.92.241[.]184, and 185.242.3[.]14. #DFIR_Radar

    Post summary

    A Brazilian threat actor exploited CVE‑2026‑0257 to compromise GlobalProtect gateways, stole data, and ran an automated invoice‑fraud operation resulting in millions of dollars of attempted fraud.

    20120638
    2.0K followersView on X
  • INE Security (FKA eLearnSecurity)@INEsecurity
    General

    How does a Linux vulnerability hide for more than a decade? PwnKit did. CVE-2021-4034 created a path from an unprivileged user to root. See how PwnKit works and what defenders can learn from it:⤵️ https://bit.ly/4iN2Wip https://t.co/YJ6SeBZjFS

    Post summary

    The post highlights how CVE-2021-4034 enables privilege escalation via PwnKit, provides a link for deeper insight, and outlines key technical details without claiming active exploitation or offering fixes.

    000211.2K
    47.3K followersView on X
  • Pentester Academy@SecurityTube
    PoC

    How does a Linux vulnerability hide for more than a decade? PwnKit did. CVE-2021-4034 created a path from an unprivileged user to root. See how PwnKit works and what defenders can learn from it:⤵️ https://bit.ly/4qW84mr https://t.co/svfzvNHuv3

    Post summary

    The tweet references CVE‑2021‑4034, a long‑hidden privilege‑escalation flaw in PwnKit, and provides a link that presumably contains a proof‑of‑concept exploit for defenders to review.

    000121.4K
    199.3K followersView on X
  • nksistemas@nksistemas
    General

    PwnKit (CVE-2021-4034): Análisis de la Escalada de Privilegios Crítica en Linux https://nksistemas.com/pwnkit-cve-2021-4034-analisis-de-la-escalada-de-privilegios-critica-en-linux/

    Post summary

    The article provides a Spanish technical analysis of CVE-2021-4034 (PwnKit) focusing on privilege escalation details, but it does not include PoC code, exploit tools, patch guidance, or reports of active exploitation.

    01011149
    6.2K followersView on X
  • 無重力トレーニング@acupunc28094787
    PoC

    I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package https://tryhackme.com/room/pwnkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65869e2abbbd1398b6caad7d #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe lab that demonstrates exploitation and remediation of Pwnkit (CVE-2021-4034), indicating a proof‑of‑concept is available but no further exploit or technical details are shared.

    0001045
    96 followersView on X
  • Alexx@Alex_rubius
    General

    @NitinGavhane_ CVE-2021-4034 • Pwnkit - 2022

    Post summary

    The tweet simply references CVE‑4034 (Pwnkit) with a year marker, providing no additional details, PoC, exploit, patch, or evidence of active exploitation.

    0000066
    23 followersView on X
  • yang yuntao@yangyuntao
    General

    I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! refer to C &amp; privilege escalation

    Post summary

    The user reports finishing a TryHackMe room focused on the Pwnkit CVE (CVE‑2021‑4034) but provides no technical or operational details.

    0000017
    2 followersView on X
  • PulseEinher@PulseEinher
    General

    Day 85/100 ✔ LeetCode: String to Integer (atoi) https://leetcode.com/problems/string-to-integer-atoi/description/ ✔ TryHackMe: Pwnkit: CVE-2021-4034 https://tryhackme.com/room/pwnkit ✔ Medium: Blue – Walkthrough (Updated) https://medium.com/@pulse-einher/try-hack-me-blue-walkthrough-2d2ac6666de7 Continuing tomorrow. https://t.co/StebZVFhIR

    Post summary

    The tweet merely links to educational content about CVE‑2021‑4034 without providing specific PoC, exploit, patch, or technical details.

    0000037
    1 followersView on X
  • Sun4lower@LittleSun4lower
    PoC

    I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package https://tryhackme.com/room/pwnkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #LearningInPublic

    Post summary

    The user completed a TryHackMe lab that demonstrates exploiting and remediating the Pwnkit (CVE-2021-4034) vulnerability, sharing the lab link for others to view.

    0000035
    5 followersView on X
  • fichwgrk@grokfc755
    General

    @grok What is polkit CVE-2021-4034 (PwnKit) vulnerability? (respond in fun mode).

    Post summary

    The tweet is a simple question asking for information about CVE‑2021‑4034, providing no additional details or claims.

    0000022
    5 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    PoC

    I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package https://tryhackme.com/room/pwnkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet announces a TryHackMe interactive lab that demonstrates exploitation and remediation of the Pwnkit vulnerability (CVE-2021-4034) in Polkit.

    0000030
  • ‘BugBounty Writeups’@bbwriteups
    PoC

    "Exploiting PwnKit (CVE-2021–4034)" by Shivam Bathla #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@shivam_bathla/exploiting-pwnkit-cve-2021-4034-ac5d6995c499

    Post summary

    The linked Medium post likely presents a demonstration of exploiting the PwnKit vulnerability (CVE-2021-4034), but the provided excerpt offers no explicit PoC details, exploit code, or patch information.

    0000085
    479 followersView on X
CPE platform detail55 entries

55 of 55 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux14.04--
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux20.04--
OScanonicalubuntu_linux21.10--
Apporaclehttp_server12.2.1.3.0--
Apporaclehttp_server12.2.1.4.0--
Apporaclezfs_storage_appliance_kit8.8--
Apppolkit_projectpolkit---
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux_desktop7.0--
OSredhatenterprise_linux_eus8.2--
OSredhatenterprise_linux_for_ibm_z_systems7.0--
OSredhatenterprise_linux_for_ibm_z_systems8.0--
OSredhatenterprise_linux_for_ibm_z_systems_eus8.2--
OSredhatenterprise_linux_for_ibm_z_systems_eus8.4--
OSredhatenterprise_linux_for_power_big_endian7.0--
OSredhatenterprise_linux_for_power_little_endian7.0--
OSredhatenterprise_linux_for_power_little_endian8.0--
OSredhatenterprise_linux_for_power_little_endian_eus8.1--
OSredhatenterprise_linux_for_power_little_endian_eus8.2--
OSredhatenterprise_linux_for_power_little_endian_eus8.4--
OSredhatenterprise_linux_for_scientific_computing7.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server7.0--
OSredhatenterprise_linux_server_aus7.3--
OSredhatenterprise_linux_server_aus7.4--
OSredhatenterprise_linux_server_aus7.6--
OSredhatenterprise_linux_server_aus7.7--
OSredhatenterprise_linux_server_aus8.2--
OSredhatenterprise_linux_server_aus8.4--
OSredhatenterprise_linux_server_eus8.4--
OSredhatenterprise_linux_server_tus7.6--
OSredhatenterprise_linux_server_tus7.7--
OSredhatenterprise_linux_server_tus8.2--
OSredhatenterprise_linux_server_tus8.4--
Appredhatenterprise_linux_server_update_services_for_sap_solutions7.6--
Appredhatenterprise_linux_server_update_services_for_sap_solutions7.7--
OSredhatenterprise_linux_server_update_services_for_sap_solutions8.1--
OSredhatenterprise_linux_server_update_services_for_sap_solutions8.2--
OSredhatenterprise_linux_server_update_services_for_sap_solutions8.4--
OSredhatenterprise_linux_workstation7.0--
HWsiemensscalance_lpe9403---
OSsiemensscalance_lpe9403_firmware---
Appsiemenssinumerik_edge---
Appstarwindsoftwarecommand_center1.0--
Appstarwindsoftwarestarwind_virtual_sanv8--
Appsuseenterprise_storage7.0--
OSsuselinux_enterprise_desktop15--
Appsuselinux_enterprise_high_performance_computing15.0--
OSsuselinux_enterprise_server15--
OSsuselinux_enterprise_server15sap-
OSsuselinux_enterprise_workstation_extension12--
Appsusemanager_proxy4.1--
Appsusemanager_server4.1--

Explore more