In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.
[
{
"events": [
{
"introduced": "9.2.0"
},
{
"fixed": "9.2.10"
}
]
},
{
"events": [
{
"introduced": "9.3.0"
},
{
"fixed": "9.3.8"
}
]
},
{
"events": [
{
"introduced": "9.4.0"
},
{
"fixed": "9.4.6"
}
]
},
{
"events": [
{
"introduced": "10.0.0"
},
{
"fixed": "10.0.2"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-20387.json"