CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2016-2568: pkexec, when used with --user nonpriv, allows local users to escape to the parent session

highCVSS 7.8CVE-2016-2568

CSIRTS triage

What
pkexec with --user flag allows local users to escape the target session and return to the parent session with elevated privileges.
Who is affected
Systems with Polkit installed where unprivileged users can execute pkexec with --user parameter.
Urgency
High; CVSS 7.8 and local privilege escalation with straightforward exploitation path.
Action
Upgrade Polkit to a version that fixes session boundary enforcement or disable pkexec --user functionality.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Polkit

Get an email when a new Polkit advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
high — CVSS 7.8
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-2568

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2016-2568coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center