Zabbix Agent
cpe:2.3:a:zabbix:zabbix-agent:*:*:*:*:*:*:*
- >= 6.0.0, <= 6.0.40
- >= 7.0.0, <= 7.0.17
- >= 7.2.0, <= 7.2.11
- >= 7.4.0, <= 7.4.1
A vulnerability exists in Zabbix Agent and Agent 2 for Windows, where the OpenSSL configuration file is loaded from a user-writable path. This flaw allows low-privileged users to maliciously alter the configuration, potentially leading to local privilege escalation by injecting a DLL. The issue arises because the modified configuration file is only loaded after restarting Zabbix Agent or the system.
Exploitation of this vulnerability could result in unauthorized DLL injection, allowing for local privilege escalation on the affected Windows system.
A local Windows user with Zabbix Agent or Zabbix Agent 2 installed can modify the OpenSSL configuration file. The injected DLL will be executed the next time Zabbix Agent is started or the system is rebooted.
Users can update to Zabbix Agent version 6.0.41, 7.0.18, 7.2.12, or 7.4.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.