In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:Program FilesSplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Universal_forwarder | Splunk | 9.1.0 (including) | 9.1.9 (excluding) |
Universal_forwarder | Splunk | 9.2.0 (including) | 9.2.6 (excluding) |
Universal_forwarder | Splunk | 9.3.0 (including) | 9.3.4 (excluding) |
Universal_forwarder | Splunk | 9.4.0 (including) | 9.4.2 (excluding) |