« Back to list

CVE-2011-4945

Status: ModifiedMedium (6.9)—

PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2011-4945",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-01T23:55:00.800",
  "references": [
    {
      "url": "http://cgit.freedesktop.org/PolicyKit/commit/?id=763faf434b445c20ae9529100d3ef5290976d0c9",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://patch-tracker.debian.org/patch/series/view/policykit-1/0.104-2/05_revert-admin-identities-unix-group-wheel.patch",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/48817",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201204-06.xml",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mail-archive.com/polkit-devel%40lists.freedesktop.org/msg00327.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/03/28/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/03/28/2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=401513",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://launchpad.net/ubuntu/+source/policykit-1/0.103-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://cgit.freedesktop.org/PolicyKit/commit/?id=763faf434b445c20ae9529100d3ef5290976d0c9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://patch-tracker.debian.org/patch/series/view/policykit-1/0.104-2/05_revert-admin-identities-unix-group-wheel.patch",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48817",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201204-06.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mail-archive.com/polkit-devel%40lists.freedesktop.org/msg00327.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/03/28/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/03/28/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=401513",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://launchpad.net/ubuntu/+source/policykit-1/0.103-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PolicyKit 0.103 sets the AdminIdentities to \"wheel\" by default, which allows local users in the wheel group to gain root privileges without authentication."
    },
    {
      "lang": "es",
      "value": "PolicyKit v0.103 fija AdminIdentities a \"wheel\" por defecto, lo que permite a usuarios locales en el grupo wheel para obtener privilegios de root sin autentificación."
    }
  ],
  "lastModified": "2026-06-16T23:35:40.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:michael_biebl:policykit:0.103:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCE41E05-00E9-4E9B-8489-56589B10C16E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}