CVE-2025-20298

Published Jun 2, 2025

Last updated 4 months ago

CVSS high 8.0
Splunk Universal Forwarder

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-20298 is a vulnerability found in Splunk Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9. The vulnerability stems from incorrect permission assignments during the installation or upgrade process. This results in non-administrator users being able to access the Universal Forwarder installation directory, which is by default located at C:\Program Files\SplunkUniversalForwarder. This access could lead to unauthorized modification of executable files or configurations, potential replacement of service binaries resulting in arbitrary code execution with elevated privileges, and exposure or tampering of sensitive log data.

Description
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
Source
psirt@cisco.com
NVD status
Analyzed
Products
universal_forwarder

Risk scores

CVSS 3.1

Type
Primary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@cisco.com
CWE-732

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.