← voltar
CVE-2025-20298

Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgrade

CVSS 8 HIGHEPSS 0.2%CWE-732
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
02 jun 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →