#VU119138 Incorrect permission assignment for critical resource in Splunk Universal Forwarder - CVE-2025-20387
Published: December 4, 2025
Splunk Universal Forwarder
Splunk Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due incorrect permissions assignment for Windows Installation directory (by default, C:\\Program Files\\SplunkUniversalForwarder) during new installation or upgrade. A local user on the machine can access the directory and all its contents.