Splunk Enterprise Vulnerabilities Allows Privileges Escalation Via Incorrect File Permissions
ID: 2ba1dd59-7657-5fd0-8f1d-011e764a4156
STIX ID: report--2ba1dd59-7657-5fd0-8f1d-011e764a4156
Feed Name: cybersecurityNews.com
A high-severity improper file-permission vulnerability (CVE-2025-20386 for Enterprise and CVE-2025-20387 for Universal Forwarder) in Splunk for Windows can grant unprivileged local users read/write access to installation directories and sensitive configuration files, enabling code injection or privilege escalation; Splunk rates it CVSS 8.0 and provides patched versions (Enterprise/Forwarder 10.0.2, 9.4.6, 9.3.8, 9.2.10) plus icacls-based mitigations — organizations should prioritize patching given Splunk’s widespread deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
