Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16672 | In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents. |
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-0602 |
|
Mon, 04 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Splunk Splunk universal Forwarder |
|
| CPEs | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows Splunk Splunk universal Forwarder |
Mon, 02 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents. | |
| Title | Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgrade | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2025-06-02T17:24:12.974Z
Reserved: 2024-10-10T19:15:13.252Z
Link: CVE-2025-20298
Updated: 2025-06-02T17:24:09.334Z
Status : Analyzed
Published: 2025-06-02T18:15:23.560
Modified: 2025-08-04T18:19:54.633
Link: CVE-2025-20298
No data.
OpenCVE Enrichment
No data.
EUVD