Zabbix Agent and Agent 2 for Windows Vulnerability Let Attackers Escalate Privileges
A security vulnerability has been identified in Zabbix Agent and Agent 2 for Windows, enabling attackers with local system access to escalate privileges via DLL injection attacks.
A security vulnerability has been identified in Zabbix Agent and Agent 2 for Windows, enabling attackers with local system access to escalate privileges via DLL injection attacks.
Recorded as CVE-2025-27237 with a CVSS score of 7.3 (High), this flaw affects multiple versions of the network monitoring solution, prompting Zabbix to issue immediate security updates.
The vulnerability arises from improper handling of OpenSSL configuration files in Windows environments, where the configuration path can be altered by users with limited privileges.
This exposes an attack vector where malicious actors can inject dynamic link libraries (DLLs) to achieve elevated system privileges.
Zabbix Agent Windows Local Privilege Escalation
The flaw is related to the way Zabbix Agent and Agent 2 process OpenSSL configuration files on Windows systems. These agents load the OpenSSL configuration from a file path that lacks sufficient access controls, allowing low-privileged users to modify the configuration content.
This attack requires local system access and involves altering the OpenSSL configuration file to reference a malicious DLL, which is loaded during the agent's startup or system restart.
The vulnerability affects Zabbix versions 6.0.0 through 6.0.40, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, and 7.4.0 through 7.4.1.
The attack prerequisites include existing access to the Windows system with Zabbix Agent installed, and the malicious configuration becoming effective only after the Zabbix Agent service restarts or the system reboots.
Security researcher himbeer discovered the vulnerability and reported it through Zabbix's HackerOne bug bounty program.
This exposes an attack vector where malicious actors can inject dynamic link libraries (DLLs) to achieve elevated system privileges.
The DLL injection technique exploits the trust between the Zabbix Agent service and the OpenSSL library, allowing execution of arbitrary code with elevated privileges of the agent process.
Risk Factors Details
Affected Products Zabbix Agent for Windows 6.0.0 – 6.0.40
Zabbix Agent2 for Windows 7.4.0 – 7.4.1
Impact Local privilege escalation
Exploit Prerequisites Local Windows user account
Ability to modify OpenSSL configuration file path
Agent service or system restart to load malicious DLL
CVSS 3.1 Score 7.8 (High)
Zabbix has issued security patches for all affected products to address this privilege escalation vulnerability.
The updated versions, 6.0.41, 7.0.18, 7.2.12, and 7.4.2, implement proper access controls for OpenSSL configuration file paths and validate configuration content before processing.
System administrators should promptly update their Zabbix Agent installations to the corresponding patched versions.
The company has not offered specific workarounds for this vulnerability, making security updates the primary mitigation strategy.
Organizations utilizing Zabbix monitoring infrastructure should prioritize these updates, especially in environments where multiple users have local system access or where monitoring agents operate with elevated privileges.
This security flaw could impact numerous Windows-based monitoring installations globally, given the extensive deployment of Zabbix solutions in enterprise environments.
Based on reporting by Cyber Security News.
