CVE-2025-20387: Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgrade
In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20387?
CVE-2025-20387 is considered a high severity vulnerability due to improper permission assignments.
How do I fix CVE-2025-20387?
To fix CVE-2025-20387, upgrade to Splunk Universal Forwarder for Windows version 10.0.2 or later, or 9.4.6, 9.3.8, or 9.2.10.
What are the affected versions for CVE-2025-20387?
The affected versions for CVE-2025-20387 include Splunk Universal Forwarder for Windows versions prior to 10.0.2, 9.4.6, 9.3.8, and 9.2.10.
Can non-administrator users exploit CVE-2025-20387?
Yes, non-administrator users can exploit CVE-2025-20387 due to incorrect permissions in the installation directory.
Is there a known workaround for CVE-2025-20387?
There are no official workarounds for CVE-2025-20387; upgrading to a fixed version is recommended.