CVE-2024-36984: Remote Code Execution through Serialized Session Payload in Splunk Enterprise on Windows

8.8 CVSS

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

Classification

CVE ID: CVE-2024-36984

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

Affected Products

Vendor: Splunk

Product: Splunk Enterprise

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://advisory.splunk.com/advisories/SVD-2024-0704
https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/

Timeline