Elastic high stable eql
Potential Privilege Escalation via PKEXEC
Identifies an attempt to exploit a local privilege escalation in polkit pkexec (CVE-2021-4034) via unsecure environment variable injection. Successful exploitation allows an unprivileged user to escalate to the root user.
Detection Logic
file where host.os.type == "linux" and file.path : "/*GCONV_PATH*" Field Validations
Loading…
Comments (0)
Loading comments...