The Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Linux vulnerability known as PwnKit to the list of bugs being exploited by hackers.

See also: Walmart: Denies being attacked by Yanluowang ransomware
The security flaw, identified as CVE-2021-4034, was discovered in Polkit's pkexec component used by all major distributions (including Ubuntu, Debian, Fedora , and CentOS).
PwnKit is a memory corruption bug that can be exploited by unprivileged users to gain full root privileges on Linux systems with default configurations.
Qualys information security researchers who discovered it found that its origins date back to the original commit of pkexec, meaning it affects all Polkit releases. It has also been hiding in plain sight for more than 12 years since pkexec was first released in May 2009.
The credible proof-of-concept (PoC) exploit code was shared online less than three hours after Qualys published technical details for PwnKit.
Qualys urged Linux admins to expedite the security of vulnerable servers using the patches released by the Polkit development team to the GitLab repository.
This is even more pressing given that, according to the Qualys advisory, exploiting the PwnKit privilege escalation flaw is possible without leaving any traces on the compromised system.
See also: YTStealer malware steals accounts from YouTube creators

Federal services must be repaired within 3 weeks
The US cybersecurity agency has given all Federal Civilian Executive Branch Agencies (FCEB) three weeks, until July 18, to patch their Linux servers against PwnKit and block exploitation attempts .
According to a binding operational directive (BOD 22-01) issued by CISA in November to reduce the risk of known exploitable bugs in U.S. federal networks, FCEB agencies must secure their systems against bugs added to the Known Exploited Vulnerabilities Catalog (KEV).
Although this guidance only applies to federal agencies, CISA strongly urged all US organizations from the private and public sectors to prioritize fixing this bug.
Following the service's advice should reduce the attack surface that threat actors can target in attacks designed to undermine unpatched servers and compromise vulnerable networks .
See also: FBI: Criminals are using deepfakes in interviews for remote tech jobs
CISA has urged both government agencies and private sector organizations using Microsoft Exchange to accelerate the transition from legacy Basic Auth authentication methods to alternative modern authentication solutions.
Information source: bleepingcomputer.com
