Skip to main content

CVE-2021-3560

7.8
HIGHCVSS v3.1 Base Score
6.41%
LOW RiskEPSS (91st percentile)
KEV

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Published: 2/16/2022
Modified: 11/6/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Red Hat Polkit Incorrect Authorization Vulnerability

Vendor / Product:

Red Hat Polkit

Required Action:

Apply updates per vendor instructions.

Due Date: 6/2/2023(OVERDUE)
Added to KEV:

5/12/2023

Notes:

https://bugzilla.redhat.com/show_bug.cgi?id=1961710; https://nvd.nist.gov/vuln/detail/CVE-2021-3560

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

6.41%LOW Exploitation Risk
91st percentile

This vulnerability has a 6.41% probability of being exploited in the next 30 days, ranking higher than 91% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-754, CWE-863)

CVE-2026-21689MEDIUM 6.5

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccProfileXml::ParseBasic()` at `IccXML/IccLibXML/IccProfileXml.cpp`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

1/7/2026
CVE-2025-66378MEDIUM 5.9

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

12/25/2025
CVE-2025-43336MEDIUM 4.4

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app with root privileges may be able to access private information.

11/4/2025
CVE-2025-55177MEDIUM 5.4

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

8/29/2025
CVE-2025-36157CRITICAL 9.8

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.

8/24/2025

Similar SeverityHIGH