Description
This Metasploit module exploits a Remote Code Execution (RCE) vulnerability in Splunk Enterprise (splunk_archiver application).
The flaw is rooted in the unsafe use of a Splunk lookup function, specifically | copybuckets, within the splunk_archiver application, which ultimately leads to the execution of the helper script sudobash with attacker-controlled arguments.
The affected versions include any release prior to 9.0.10, as well as versions 9.1.2 through 9.1.5 and 9.2.0 through 9.2.2.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/splunk_auth_rce_cve_2024_36985msf undefined(splunk_auth_rce_cve_2024_36985) > show actions ...actions...msf undefined(splunk_auth_rce_cve_2024_36985) > set ACTION < action-name >msf undefined(splunk_auth_rce_cve_2024_36985) > show options ...show and set options...msf undefined(splunk_auth_rce_cve_2024_36985) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub