CVE-2021-3560 – Polkit – Local Privilege Escalation
by CIRT Team
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user.
This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data
confidentiality and integrity as well as system availability.
The vulnerability enables an unprivileged local user to get a root shell on the system.
Updates are available.Please see the references or vendor advisory for more information.
26 Oct 2023 - Security Advisories & Alerts