CVE-2023-40596 is a high-severity privilege escalation vulnerability affecting Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1 on Windows. An attacker with local access can exploit an insecure DLL path reference to OPENSSLDIR, allowing them to install malicious code and gain elevated privileges. With a CVSS score of 8.8, this vulnerability has a low attack complexity and no user interaction required, leading to high impacts on confidentiality, integrity, and availability. While not currently in CISA's Known Exploited Vulnerabilities catalog, there is no public exploit code available, and community discussion and media coverage are minimal, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.2.0, < 8.2.12CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 9.0.0, < 9.0.6CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
9.1.0CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:9.1.0:*:*:*:enterprise:*:*:* | ||
>= 8.2, < 8.2.12CPE match | cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.0.6CPE match | cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.