CVE-2025-20298
02.06.2025, 18:15
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.Enginsight
Vendor | Product | Version |
---|---|---|
splunk | universal_forwarder | 9.1.0 ≤ 𝑥 < 9.1.9 |
splunk | universal_forwarder | 9.2.0 ≤ 𝑥 < 9.2.6 |
splunk | universal_forwarder | 9.3.0 ≤ 𝑥 < 9.3.4 |
splunk | universal_forwarder | 9.4.0 ≤ 𝑥 < 9.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration