Impact
A local Windows user can pre‑bind to the Splunk management port before the Splunk Enterprise service starts, intercept authentication tokens from child processes, and use those tokens to gain full access to all data and system integrity that the Splunk service account normally holds. This flaw arises because the Windows listener does not enforce exclusive address binding prior to startup, allowing a local attacker to hijack the token exchange and effectively inject credentials into the Splunk environment. The result is that a user who would normally only have limited local rights can climb to the privileges associated with the Splunk service account, which may include sensitive data, configuration, and administrative actions. The weakness is classified as CWE‑269: Improper Privilege Management.
Affected Systems
Splunk Enterprise running on Windows versions prior to 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14 is vulnerable. Any deployment of these affected releases that exposes the management port to local users is at risk.
Risk and Exploitability
The stored CVSS score of 8.8 indicates a high severity attack. Because the flaw requires local user access to the Windows host, the attack vector is local, and the attacker can exploit the vulnerability after binding to the port before Splunk starts. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so while it remains a critical local privilege escalation issue, there is no known public exploitation data at this time. Administrators should treat it as a high‑priority issue and proceed with remediation as soon as possible.
OpenCVE Enrichment