Splunk Universal Forwarder
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*
- < 10.0.2
- >= 9.4.0, <= 9.4.5
- >= 9.3.0, <= 9.3.7
- >= 9.2.0, <= 9.2.9
A vulnerability exists in Splunk Universal Forwarder for Windows in versions prior to 10.0.2, as well as 9.4.0 through 9.4.5, 9.3.0 through 9.3.7, and 9.2.0 through 9.2.9. During new installations or upgrades to these affected versions, incorrect permissions can be assigned in the installation directory. This misconfiguration allows non-administrator users to access the directory and its contents.
The vulnerability could lead to unauthorized access to the Universal Forwarder installation directory and its files by non-administrator users.
Users can upgrade Splunk Universal Forwarder for Windows to versions 10.0.2, 9.4.6, 9.3.8, 9.2.10, or higher. If an upgrade is not possible, the vulnerability can be mitigated by adjusting the directory permissions using the 'icacls' command to remove access for non-administrator users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.