
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20387 is an incorrect permissions assignment vulnerability (CWE-732) in the Splunk Universal Forwarder for Windows that allows non-administrator local users to access the forwarder's installation directory and all its contents. It affects Splunk Universal Forwarder for Windows versions prior to 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and is triggered during a new installation or upgrade. The vulnerability was disclosed on December 3, 2025, by Cisco Systems (Splunk's parent company) via advisory SVD-2025-1206. CVSS v3.1 scores range from 6.5 (Medium, per NVD/NIST) to 8.0 (High, per the CNA/Cisco), reflecting differing assessments of user interaction requirements (Splunk Advisory, NVD).
The root cause is CWE-732 (Incorrect Permission Assignment for Critical Resource): during a fresh installation or upgrade of the Splunk Universal Forwarder on Windows, the installer sets overly permissive access controls on the installation directory, granting read (and potentially write) access to non-administrator users. An attacker with a low-privileged local account on the affected Windows host can browse the installation directory, read configuration files, and potentially access stored credentials or tokens without any special privileges. The attack vector is classified as network-adjacent in some assessments because the forwarder communicates with remote Splunk infrastructure, but the permission flaw itself is exploitable locally. No public proof-of-concept exploit code has been identified at this time (Splunk Advisory, NVD).
Successful exploitation allows a low-privileged local user to read sensitive forwarder configuration files, which may contain credentials, authentication tokens, or deployment server addresses used by the Splunk Universal Forwarder. This information could be leveraged to pivot to the Splunk deployment server or indexer infrastructure, potentially compromising the broader Splunk environment. The CNA (Cisco) assessed the impact as affecting confidentiality, integrity, and availability (CVSS 8.0 High), suggesting that in certain scenarios an attacker could also modify forwarder configurations or binaries to achieve privilege escalation or persistent access (Splunk Advisory, NVD, eSecurity Planet).
wmic product get name,version) or network scanning.C:\Program Files\SplunkUniversalForwarder\) and confirm read access is granted to the current user due to misconfigured ACLs.etc\system\local\inputs.conf, outputs.conf, and deploymentclient.conf to obtain deployment server addresses, credentials, or authentication tokens.C:\Program Files\SplunkUniversalForwarder\etc\ by non-administrator accounts; presence of copied configuration files in user-writable directories.inputs.conf, outputs.conf, or deploymentclient.conf by unexpected users.cmd.exe, powershell.exe) spawned under non-administrator user contexts accessing Splunk installation paths.Splunk has released patched versions of the Universal Forwarder for Windows: 10.0.2, 9.4.6, 9.3.8, and 9.2.10. Organizations should upgrade to one of these versions immediately. As an interim workaround, administrators should manually audit and restrict ACLs on the Splunk Universal Forwarder installation directory (e.g., C:\Program Files\SplunkUniversalForwarder\) to ensure only SYSTEM and Administrator accounts have access. Additionally, a security audit of existing installations should be conducted to check for unauthorized access or configuration changes, and least-privilege principles should be enforced for all local user accounts on hosts running the forwarder (Splunk Advisory).
The vulnerability received moderate coverage from cybersecurity news outlets including CyberSecurityNews, eSecurity Planet, SecurityOnline, TechRepublic, and The Hacker News (in a weekly recap), generally framing it as a privilege escalation risk requiring prompt patching (CyberSecurityNews, eSecurity Planet, The Hacker News). UpGuard and Red Hot Cyber published analyses covering both CVE-2025-20386 and CVE-2025-20387 together, noting the risk to organizations relying on Splunk for security monitoring (UpGuard). Community sentiment on social media was measured, with no significant alarm given the absence of active exploitation. Heise.de covered the issue in the context of broader Splunk security patches (Heise).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."