Home

Description

In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk Enterprise for Windows is installed on a separate drive.

PUBLISHED Reserved 2024-09-05 | Published 2024-10-14 | Updated 2025-02-28 | Assigner Splunk




HIGH: 8.0CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Problem types

The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as .. that can resolve to a location that is outside of that directory.

Product status

9.3 (custom) before 9.3.1
affected

9.2 (custom) before 9.2.3
affected

9.1 (custom) before 9.1.6
affected

Credits

Alex Hordijk (hordalex)

References

advisory.splunk.com/advisories/SVD-2024-1001

research.splunk.com/...c97e0704-d9c6-454d-89ba-1510a987bf72/

cve.org (CVE-2024-45731)

nvd.nist.gov (CVE-2024-45731)

Download JSON