mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
b9edc5464e
* [New Rule] Potential Privilege Escalation via PKEXEC Identifies attempt to exploit a local privilege escalation in polkit pkexec (CVE-2021-4034) via unsecure environment variable injection. Successful exploitation allows an unprivileged user to escalate to the root user : * Update privilege_escalation_pkexec_envar_hijack.toml * removed = sign