CVE-2024-36984: Remote Code Execution through Serialized Session Payload in Splunk Enterprise on Windows
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36984?
CVE-2024-36984 is classified as a high severity vulnerability due to its potential to allow authenticated users to execute arbitrary code.
How do I fix CVE-2024-36984?
To remediate CVE-2024-36984, upgrade Splunk Enterprise to version 9.2.2 or later, 9.1.5 or later, or 9.0.10 or later.
Who is affected by CVE-2024-36984?
CVE-2024-36984 affects authenticated users of Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 running on Windows.
What impact does CVE-2024-36984 have on systems?
CVE-2024-36984 can lead to arbitrary code execution, allowing attackers to potentially take control of affected systems.
How can I identify if my system is vulnerable to CVE-2024-36984?
You can identify if your system is vulnerable to CVE-2024-36984 by checking the version of Splunk Enterprise installed against the affected version criteria.