← Vulnerability feed

Vulnerability record · CVE-2025-20298 · published 2 June 2025

CVE-2025-20298: Splunk universal forwarder incorrect permission assignment vulnerability

Splunk · Universal Forwarder

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.

8.0 CVSS 3.1 High EPSS 0.29% · top 80.5% CWE-732 · Incorrect permission assignment
8.0CVSS 3.1 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20298 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-32221Haxx curl information exposure vulnerabilityWhen doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOP…EPSS 4.4%9.8CVE-2022-36227Libarchive null pointer dereference vulnerabilityIn libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the functio…EPSS 2.4%9.8CVE-2022-32207Haxx curl incorrect default permissions vulnerabilityWhen curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from …EPSS 7.7%9.8CVE-2021-3520Lz4 project lz4 integer overflow vulnerabilityThere's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading t…EPSS 3.2%9.1CVE-2023-23914Haxx curl cleartext transmission vulnerabilityA cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs a…EPSS 0.86%9.1CVE-2021-22945Haxx libcurl double free vulnerabilityWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory a…EPSS 6.7%8.8CVE-2023-27533Haxx curl injection vulnerabilityA vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously c…EPSS 2.0%8.8CVE-2023-27534Haxx curl path traversal vulnerabilityA path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2025-20298), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.