CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-3560

🔥 Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score42.5550%
EPSS Percentile98.95th
Published2022-02-16
Last Modified2026-06-17
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected Platforms (CPE)

📦
Polkit Project

Polkit

< 0.119
💻
Debian

Debian Linux

= 11.0
💻
Canonical

Ubuntu Linux

= 20.04
📦
Redhat

Virtualization

= 4.0

References & Advisories

相关漏洞威胁