CVE-2013-6773: High severity splunk vulnerability
Published Jan 23, 2020
·Updated
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
Affected Software
2 affected components
Splunk splunk>=5.0<5.0.3
Microsoft Windows
Event History
Jan 23, 2020
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6773?
CVE-2013-6773 is classified as a medium severity vulnerability due to its ability to allow privilege escalation.
2
How do I fix CVE-2013-6773?
To mitigate CVE-2013-6773, ensure that the Splunk Universal Forwarder service path is correctly quoted to avoid unquoted service path vulnerabilities.
3
Which versions of Splunk are affected by CVE-2013-6773?
CVE-2013-6773 affects Splunk versions from 5.0 to 5.0.3.
4
Can CVE-2013-6773 affect my Windows system?
Yes, CVE-2013-6773 can affect Windows systems where Splunk 5.0.3 is installed and configured with an unquoted service path.
5
What should I do if I am using an affected version of Splunk with CVE-2013-6773?
If you are using an affected version of Splunk, it is recommended to upgrade to a later version or apply necessary patches that address this vulnerability.