PT-2026-78731 · Splunk · Splunk Enterprise
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise for Windows versions prior to 10.4.2
Splunk Enterprise for Windows versions prior to 10.2.6
Splunk Enterprise for Windows versions prior to 10.0.9
Splunk Enterprise for Windows versions prior to 9.4.13
Splunk Enterprise for Windows versions prior to 9.3.14
Description
A local user with access to the Windows host can bind to the management port before the service starts. This occurs because the Windows management-port listener fails to apply exclusive address binding protections. An attacker can intercept authentication tokens from child processes to compromise system integrity and access data available to the account running the software.
Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.13 or later.
Update to version 9.3.14 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise