Splunk Universal Forwarder for Windows Vulnerability Lets Non-Admin Users Access All Data

A critical security vulnerability has been discovered in Splunk’s Universal Forwarder for Windows that could allow unauthorized access to sensitive system directories.

The vulnerability, tracked as CVE-2025-20298 and assigned a CVSS score of 8.0 (High), affects installations and upgrades of Universal Forwarder versions across multiple release branches.

Security researchers have identified that during new installations or upgrades to affected versions, incorrect permission assignments occur in the Universal Forwarder installation directory, potentially exposing sensitive data to non-administrator users on the same machine.

The vulnerability stems from improper permission configuration during the installation or upgrade process of Splunk Universal Forwarder for Windows.

When users install or upgrade to an affected version, the system incorrectly assigns permissions to the Universal Forwarder installation directory, which is typically located at C:\Program Files\SplunkUniversalForwarder.

This misconfiguration allows any non-administrator user with access to the Windows machine to read, access, and potentially modify all contents within the installation directory.

The security flaw is classified under CWE-732 (Incorrect Permission Assignment for Critical Resource) and carries significant risk implications.

With a CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H, the vulnerability demonstrates high impact on confidentiality, integrity, and availability.

The “Network” attack vector indicates that remote exploitation is possible, while the “Low” attack complexity suggests that minimal specialized conditions are required for successful exploitation.

The requirement for low-level privileges and user interaction provides some mitigation, but the potential for complete system compromise remains substantial.

Splunk Vulnerability

System administrators can manually correct the permission assignment by executing a specific command from an elevated command prompt or PowerShell window.

The affected versions include all releases below 9.4.2 in the 9.4 branch, versions below 9.3.4 in the 9.3 branch, releases below 9.2.6 in the 9.2 branch, and versions below 9.1.9 in the 9.1 branch.

Organizations running any of these vulnerable versions should prioritize immediate remediation efforts.

The company has released patched versions across all affected branches to address the security issue.

Users should upgrade to Universal Forwarder for Windows version 9.4.2 or higher for the 9.4 branch, version 9.3.4 or higher for the 9.3 branch, version 9.2.6 or higher for the 9.2 branch, or version 9.1.9 or higher for the 9.1 branch.

These fixed versions include proper permission assignment mechanisms that prevent unauthorized access to the installation directory.

Mitigations

For organizations unable to immediately upgrade to patched versions, Splunk has provided a specific mitigation strategy to address the vulnerability.

Splunk has confirmed that multiple version branches of Universal Forwarder for Windows are susceptible to this Splunk vulnerability .

The recommended command is icacls.exe "<path\to\installation\directory>" /remove:g *BU /C, which must be run with Windows system administrator privileges after installing the affected Splunk version.

This mitigation should be implemented in three critical scenarios: during new installations of affected versions, when upgrading to an affected version, and after uninstalling and reinstalling an existing affected Splunk version.

Security teams should also conduct thorough audits of existing Universal Forwarder installations to identify potentially compromised systems and assess whether unauthorized access may have already occurred.

Regular security assessments and prompt application of security updates remain essential for maintaining robust cybersecurity postures in enterprise environments.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mayura
Mayura
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Trending News

Related Stories