PT-2025-48959 · Splunk · Splunk Universal Forwarder For Windows

Published

2025-12-03

·

Updated

2025-12-08

·

CVE-2025-20387

CVSS v2.0

9.0

High

AV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Splunk Universal Forwarder for Windows versions prior to 10.0.2 Splunk Universal Forwarder for Windows versions prior to 9.4.6 Splunk Universal Forwarder for Windows versions prior to 9.3.8 Splunk Universal Forwarder for Windows versions prior to 9.2.10
Description A new installation or upgrade to an affected version of Splunk Universal Forwarder for Windows can lead to incorrect permissions being assigned within the Universal Forwarder for Windows installation directory. This allows non-administrator users on the system to access the directory and its contents.
Recommendations Upgrade to Splunk Universal Forwarder for Windows version 10.0.2 or later. Upgrade to Splunk Universal Forwarder for Windows version 9.4.6 or later. Upgrade to Splunk Universal Forwarder for Windows version 9.3.8 or later. Upgrade to Splunk Universal Forwarder for Windows version 9.2.10 or later.

Fix

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-16302
CVE-2025-20387

Affected Products

Splunk Universal Forwarder For Windows