VYPR
High severity8.0NVD Advisory· Published Jun 2, 2025· Updated Jun 17, 2026

CVE-2025-20298

CVE-2025-20298

Description

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*range: >=9.1.0,<9.1.9
    • (no CPE)range: <9.4.2, <9.3.4, <9.2.6, <9.1.9
  • Splunk/Splunk/UniversalForwarder for Windowsv5
    Range: 9.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.