CVE-2024-36984

Remote Code Execution through Serialized Session Payload in Splunk Enterprise on Windows

Severity
High 8.8
CVSS 3.1
Exploited
Not listed
EPSS
0.014
70.6th percentile
Discovered by
Not disclosed
Published
Jul 1, 2024
Assigned by splunk

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

Weakness: CWE-502

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management affected-vendor
Cisco Splunk Enterprise Security SIEM & Log Management affected-vendor
Vendor-reported products (2)
  • Splunk · Splunk Enterprise
  • splunk · enterprise_security

Credit

Danylo Dmytriiev (DDV_UA)

Something wrong here?