CVE-2024-45731
Potential Remote Command Execution (RCE) through arbitrary file write to Windows system root directory when Splunk Enterprise for Windows is installed on a separate disk
Severity
High 8
CVSS 3.1
Exploited
Not listed
EPSS
0.005
42.7th percentile
Discovered by
Not disclosed
Published
Oct 14, 2024
Assigned by splunk
Description
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk Enterprise for Windows is installed on a separate drive.
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | affected-vendor |
Vendor-reported products (2)
- Splunk · Splunk Enterprise
- splunk · splunk_enterprise
Credit
Alex Hordijk (hordalex)