Tracker / CVE-2023-40596
CVE-2023-40596
Alta 7.0
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.
Prodotti e versioni affette
| splunk | splunk |
|---|---|
| splunk | splunk · 8.2.0 → 8.2.12 |
| splunk | splunk · 9.0.0 → 9.0.6 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.