Splunk Multiple Local Privilege Escalation Vulnerabilities
BID:101664
CVE-2017-18348 |Info
Splunk Multiple Local Privilege Escalation Vulnerabilities
| Bugtraq ID: | 101664 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 27 2017 12:00AM |
| Updated: | Dec 19 2017 10:36PM |
| Credit: | Hank Leininger of KoreLogic, Inc. |
| Vulnerable: |
Splunk Splunk Universal Forwarder 0 Splunk Splunk Light 0 Splunk Splunk Enterprise 6.6.3 Splunk Splunk Enterprise 6.6.2 Splunk Splunk Enterprise 6.6.1 Splunk Splunk Enterprise 6.6 |
| Not Vulnerable: | |
Discussion
Splunk Multiple Local Privilege Escalation Vulnerabilities
Splunk is prone to multiple local privilege escalation vulnerabilities.
An attacker can exploit these issues to to execute arbitrary code with root privileges.
Splunk is prone to multiple local privilege escalation vulnerabilities.
An attacker can exploit these issues to to execute arbitrary code with root privileges.
Exploit / POC
Splunk Multiple Local Privilege Escalation Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Splunk Multiple Local Privilege Escalation Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Splunk Multiple Local Privilege Escalation Vulnerabilities
References:
References:
- Splunk Homepage (Splunk)
- Splunk response to Potential Local Privilege Escalation through instructions to (Splunk)
- Splunk Local Privilege Escalation (Hank Leininger)