Falco high stable other

Polkit Local Privilege Escalation Vulnerability (CVE-2021-4034)

This rule detects attempts to exploit a privilege escalation vulnerability in Polkit's pkexec. Through the execution of specially crafted code, a local user can exploit this weakness to attain root privileges on a compromised system. This rule is highly specific in its scope.

View Source

Detection Logic

spawned_process and user.loginuid != 0 and proc.name=pkexec and proc.args = ''

Field Validations

Loading…

Comments (0)

Loading comments...