#VU93570 Deserialization of Untrusted Data in Splunk Enterprise - CVE-2024-36984
Published: July 1, 2024
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote user can pass specially crafted data to the application and execute arbitrary code on the target system.
Note, the vulnerability affects Splunk Enterprise on Windows.