Local privilege escalation via a default path in Splunk Enterprise Windows

Advisory ID: SVD-2022-0501

CVE ID: CVE-2021-42743

Published: 2022-05-03

Last Update: 2022-05-03

CVSSv3.1 Score: 8.8, High

CWE: CWE-427

Bug ID: SPL-195186

Description

A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.

Solution

Upgrade Splunk Enterprise Window versions to 8.1.1 or later.

Product Status

ProductVersionComponentAffected VersionFix Version
Splunk Enterprise8.1-8.1.0 and earlier8.1.1
Splunk Enterprise8.2-Not affected-

The vulnerability does not impact Splunk Cloud Platform instances.