HomeSecurityVulnerabilities in Splunk Enterprise allow hackers to execute remote code

Vulnerabilities in Splunk Enterprise allow hackers to execute remote code

Splunk - severity vulnerabilities in its Enterprise product that could allow hackers to execute remote code on affected systems.

Splunk Enterprise

These vulnerabilities affect multiple versions of Splunk Enterprise and Splunk Cloud Platform.

See related: Corfu: Underage hacker breached e-shop and shopped almost for free!

One of the most severe flaws, known as CVE-2024-45733, affects Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6. This vulnerability allows low-privileged users, without administrator roles or authority, to perform remote code execution due to insecure configuration of session storage. Splunk has rated this vulnerability as High severity with a CVSS score of 8.8.

Another high-severity vulnerability, CVE-2024-45731, affects Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6. This allows a low-privileged user to write files to the Windowsif Splunk is installed on a separate drive. This could allow the injection of malicious DLLs, which, if loaded, could lead to remote code execution.

A third vulnerability, CVE-2024-45732, affects multiple versions of Splunk Enterprise and Splunk Cloud Platform. It allows low-privileged users to perform queries as the “nobody” user in the SplunkDeploymentServerConfig application, potentially gaining access to restricted data.

Read more: Netgear WiFi Extender: Vulnerabilities allow hackers to insert malicious code

Splunk has released patches to address these vulnerabilities and recommends that users upgrade to the latest versions immediately. Splunk Enterprise users should upgrade to versions 9.3.1, 9.2.3, 9.1.6, or later, depending on their current version. Splunk Cloud are actively monitored and patched by the company.

Additionally, Splunk is patching several vulnerabilities in third-party packages used in the Splunk Add-on for Amazon, including high-severity flaws in the idna and certifi packages. These vulnerabilities primarily affect cases where Splunk Web is enabled.

Splunk has released patches to address these issues and recommends users upgrade to the latest versions:

  • Splunk Enterprise: 9.3.1, 9.2.3, and 9.1.6 or later
  • Splunk Cloud Platform: 9.2.2403.103, 9.1.2312.200, 9.1.2312.110, and 9.1.2308.208 or later

For users who cannot update immediately, Splunk recommends the following:

  1. Disable Splunk Web on affected systems, especially indexes in distributed environments.
  2. Modify the local.meta file in the SplunkDeploymentServerConfig application to restrict access to knowledge objects.
  3. Make sure Splunk Enterprise is not installed on a separate disk from the system drive.
Splunk Enterprise

Organizations using affected Splunk products should immediately review the security advisories and apply the necessary updates as soon as possible to mitigate the risk of exploitation.

See also: Russian hackers APT29 target Zimbra and TeamCity servers

The discovery of these vulnerabilities highlights the importance of timely application of security, particularly for critical infrastructure and security monitoring tools like Splunk. Hackers often target such platforms due to the privileged access they provide to sensitive data and systems within organizations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS