CVE-2024-45731: Potential Remote Command Execution (RCE) through arbitrary file write to Windows system root directory when Splunk Enterprise for Windows is installed on a separate disk
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk Enterprise for Windows is installed on a separate drive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45731?
CVE-2024-45731 is classified as a low-severity vulnerability.
How do I fix CVE-2024-45731?
To mitigate CVE-2024-45731, update Splunk Enterprise to version 9.3.1, 9.2.3, or 9.1.6 or later.
Who is affected by CVE-2024-45731?
CVE-2024-45731 affects low-privileged users without 'admin' or 'power' roles in specific versions of Splunk Enterprise for Windows.
What are the affected versions in CVE-2024-45731?
The affected versions for CVE-2024-45731 are Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6.
What can low-privileged users do related to CVE-2024-45731?
Low-privileged users can write files to the Windows system root directory, specifically in the Windows System32 folder.