CVE-2024-23678

HIGH

Splunk Enterprise for Windows 9.0.0-9.0.8 - Unsafe Deserialization via Path Input

Title source: llm
STIX 2.1

Description

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
splunk/splunk 9.0.0 - 9.0.8
Published Jan 22, 2024
Tracked Since Feb 18, 2026