CVE-2025-20298 Details
Description
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
A vulnerability exists in Splunk Universal Forwarder for Windows in versions prior to 9.4.2, 9.3.4, 9.2.6, and 9.1.9. During a new installation or an upgrade to an affected version, incorrect permissions can be assigned in the default installation directory. This misconfiguration allows non-administrator users to access the directory and its contents.
Users can upgrade Splunk Universal Forwarder for Windows to versions 9.4.2, 9.3.4, 9.2.6, 9.1.9, or higher. If an upgrade is not possible, the vulnerability can be mitigated by running a command to remove group permissions for non-administrator users from the installation directory. This command can be executed as a Windows system administrator using Command Prompt or PowerShell.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-0602 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| splunk universal forwarder | >= 9.1.0, < 9.1.9 >= 9.2.0, < 9.2.6 >= 9.3.0, < 9.3.4 >= 9.4.0, < 9.4.2 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | Initial Analysis | [email protected] |
| Jun 2, 2025 | New CVE Received | [email protected] |