Unrated severityNVD Advisory· Published Jun 2, 2025· Updated Jun 2, 2025
Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgrade
CVE-2025-20298
Description
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <9.4.2, <9.3.4, <9.2.6, <9.1.9
- Splunk/Splunk/UniversalForwarder for Windowsv5Range: 9.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.