Splunk Universal Forwarder for Windows Incorrect Permissions Vulnerability

Vulnerability

A vulnerability exists in Splunk Universal Forwarder for Windows in versions prior to 10.0.2, as well as 9.4.0 through 9.4.5, 9.3.0 through 9.3.7, and 9.2.0 through 9.2.9. During new installations or upgrades to these affected versions, incorrect permissions can be assigned in the installation directory. This misconfiguration allows non-administrator users to access the directory and its contents.

Impact

The vulnerability could lead to unauthorized access to the Universal Forwarder installation directory and its files by non-administrator users.

Remediation

Users can upgrade Splunk Universal Forwarder for Windows to versions 10.0.2, 9.4.6, 9.3.8, 9.2.10, or higher. If an upgrade is not possible, the vulnerability can be mitigated by adjusting the directory permissions using the 'icacls' command to remove access for non-administrator users.

Added: Dec 3, 2025, 5:22 PM
Updated: Dec 3, 2025, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
0.6
exploitability
3.3
remediation
7.9
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.