CVE-2025-20387
Splunk Forwarder vulnerability analysis and mitigation

Overview

CVE-2025-20387 is an incorrect permissions assignment vulnerability (CWE-732) in the Splunk Universal Forwarder for Windows that allows non-administrator local users to access the forwarder's installation directory and all its contents. It affects Splunk Universal Forwarder for Windows versions prior to 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and is triggered during a new installation or upgrade. The vulnerability was disclosed on December 3, 2025, by Cisco Systems (Splunk's parent company) via advisory SVD-2025-1206. CVSS v3.1 scores range from 6.5 (Medium, per NVD/NIST) to 8.0 (High, per the CNA/Cisco), reflecting differing assessments of user interaction requirements (Splunk Advisory, NVD).

Technical details

The root cause is CWE-732 (Incorrect Permission Assignment for Critical Resource): during a fresh installation or upgrade of the Splunk Universal Forwarder on Windows, the installer sets overly permissive access controls on the installation directory, granting read (and potentially write) access to non-administrator users. An attacker with a low-privileged local account on the affected Windows host can browse the installation directory, read configuration files, and potentially access stored credentials or tokens without any special privileges. The attack vector is classified as network-adjacent in some assessments because the forwarder communicates with remote Splunk infrastructure, but the permission flaw itself is exploitable locally. No public proof-of-concept exploit code has been identified at this time (Splunk Advisory, NVD).

Impact

Successful exploitation allows a low-privileged local user to read sensitive forwarder configuration files, which may contain credentials, authentication tokens, or deployment server addresses used by the Splunk Universal Forwarder. This information could be leveraged to pivot to the Splunk deployment server or indexer infrastructure, potentially compromising the broader Splunk environment. The CNA (Cisco) assessed the impact as affecting confidentiality, integrity, and availability (CVSS 8.0 High), suggesting that in certain scenarios an attacker could also modify forwarder configurations or binaries to achieve privilege escalation or persistent access (Splunk Advisory, NVD, eSecurity Planet).

Exploitation steps

  1. Reconnaissance: Identify Windows hosts running Splunk Universal Forwarder versions below 10.0.2, 9.4.6, 9.3.8, or 9.2.10 using local enumeration tools (e.g., wmic product get name,version) or network scanning.
  2. Gain low-privileged access: Obtain any non-administrator local account on the target Windows machine (e.g., via phishing, credential reuse, or existing access).
  3. Access the installation directory: Navigate to the Splunk Universal Forwarder installation directory (typically C:\Program Files\SplunkUniversalForwarder\) and confirm read access is granted to the current user due to misconfigured ACLs.
  4. Extract sensitive data: Read configuration files such as etc\system\local\inputs.conf, outputs.conf, and deploymentclient.conf to obtain deployment server addresses, credentials, or authentication tokens.
  5. Leverage extracted credentials: Use harvested credentials or tokens to authenticate to the Splunk deployment server or indexer, potentially enabling lateral movement, data exfiltration, or further privilege escalation within the Splunk environment (Splunk Advisory, eSecurity Planet).

Indicators of compromise

  • File System: Unexpected access or modification timestamps on files within C:\Program Files\SplunkUniversalForwarder\etc\ by non-administrator accounts; presence of copied configuration files in user-writable directories.
  • Logs: Windows Security Event Log entries (Event ID 4663) showing non-administrator accounts accessing the Splunk Universal Forwarder installation directory; audit logs reflecting read access to inputs.conf, outputs.conf, or deploymentclient.conf by unexpected users.
  • Process: Unusual processes (e.g., cmd.exe, powershell.exe) spawned under non-administrator user contexts accessing Splunk installation paths.
  • Network: Unexpected outbound connections from the host to Splunk deployment servers or indexers using credentials that may have been harvested from configuration files (Splunk Advisory).

Mitigation and workarounds

Splunk has released patched versions of the Universal Forwarder for Windows: 10.0.2, 9.4.6, 9.3.8, and 9.2.10. Organizations should upgrade to one of these versions immediately. As an interim workaround, administrators should manually audit and restrict ACLs on the Splunk Universal Forwarder installation directory (e.g., C:\Program Files\SplunkUniversalForwarder\) to ensure only SYSTEM and Administrator accounts have access. Additionally, a security audit of existing installations should be conducted to check for unauthorized access or configuration changes, and least-privilege principles should be enforced for all local user accounts on hosts running the forwarder (Splunk Advisory).

Community reactions

The vulnerability received moderate coverage from cybersecurity news outlets including CyberSecurityNews, eSecurity Planet, SecurityOnline, TechRepublic, and The Hacker News (in a weekly recap), generally framing it as a privilege escalation risk requiring prompt patching (CyberSecurityNews, eSecurity Planet, The Hacker News). UpGuard and Red Hot Cyber published analyses covering both CVE-2025-20386 and CVE-2025-20387 together, noting the risk to organizations relying on Splunk for security monitoring (UpGuard). Community sentiment on social media was measured, with no significant alarm given the absence of active exploitation. Heise.de covered the issue in the context of broader Splunk security patches (Heise).

Additional resources


SourceThis report was generated using AI

Related Splunk Forwarder vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20298HIGH8
  • Splunk Forwarder logoSplunk Forwarder
  • cpe:2.3:a:splunk:universal_forwarder
NoYesJun 02, 2025
CVE-2025-20387MEDIUM6.5
  • Splunk Forwarder logoSplunk Forwarder
  • cpe:2.3:a:splunk:splunk
NoYesDec 03, 2025
CVE-2023-27537MEDIUM5.9
  • MySQL logoMySQL
  • net-misc/curl
NoYesMar 30, 2023
CVE-2023-27536MEDIUM5.9
  • MySQL logoMySQL
  • curl-debugsource
NoYesMar 30, 2023
CVE-2023-27538MEDIUM5.5
  • MySQL logoMySQL
  • seal-curl
NoYesMar 30, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management