CVE-2021-42743: Local privilege escalation via a default path in Splunk Enterprise Windows
Published May 6, 2022
·Updated
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.
Affected Software
2 affected components
Splunk splunk<8.1.1
Microsoft Windows
Event History
May 6, 2022
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-42743?
CVE-2021-42743 has a medium severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2021-42743?
To fix CVE-2021-42743, upgrade Splunk Enterprise to version 8.1.1 or later, which addresses this misconfiguration.
3
What versions of Splunk are affected by CVE-2021-42743?
CVE-2021-42743 affects all Splunk Enterprise versions prior to 8.1.1.
4
What impact does CVE-2021-42743 have on a system?
CVE-2021-42743 allows a lower privileged user to escalate their privileges to that of the Splunk user on affected systems.
5
Is CVE-2021-42743 specific to any operating system?
Yes, CVE-2021-42743 specifically affects Splunk Enterprise installations on Windows.