CVE-2023-40596 |
Description: In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.
CVSS: HIGH (7.0) EPSS Score: 0.04%
December 11th, 2024 (4 months ago)
|
CVE-2023-40595 |
Description: In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.
CVSS: HIGH (8.8) EPSS Score: 0.1%
December 11th, 2024 (4 months ago)
|
CVE-2023-3997 |
Description: Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.
CVSS: HIGH (8.6) EPSS Score: 0.06%
December 11th, 2024 (4 months ago)
|
CVE-2023-38171 |
Description: Microsoft QUIC Denial of Service Vulnerability
CVSS: HIGH (7.5) EPSS Score: 0.19%
December 11th, 2024 (4 months ago)
|
CVE-2023-38166 |
Description: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVSS: HIGH (8.1) EPSS Score: 0.23%
December 11th, 2024 (4 months ago)
|
CVE-2023-38159 |
Description: Windows Graphics Component Elevation of Privilege Vulnerability
CVSS: HIGH (7.0) EPSS Score: 0.04%
December 11th, 2024 (4 months ago)
|
CVE-2023-36902 |
Description: Windows Runtime Remote Code Execution Vulnerability
CVSS: HIGH (7.0) EPSS Score: 0.23%
December 11th, 2024 (4 months ago)
|
CVE-2023-36790 |
Description: Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
CVSS: HIGH (7.8) EPSS Score: 0.05%
December 11th, 2024 (4 months ago)
|
CVE-2023-36789 |
Description: Skype for Business Remote Code Execution Vulnerability
CVSS: HIGH (7.2) EPSS Score: 0.2%
December 11th, 2024 (4 months ago)
|
CVE-2023-36786 |
Description: Skype for Business Remote Code Execution Vulnerability
CVSS: HIGH (7.2) EPSS Score: 0.22%
December 11th, 2024 (4 months ago)
|