Description
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
Published: 2025-10-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-32239 In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
History

Mon, 06 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Zabbix
Zabbix zabbix
Zabbix zabbix-agent
Zabbix zabbix-agent2
Zabbix zabbix Agentd
Vendors & Products Microsoft
Microsoft windows
Zabbix
Zabbix zabbix
Zabbix zabbix-agent
Zabbix zabbix-agent2
Zabbix zabbix Agentd

Fri, 03 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
Title DLL injection in Zabbix Agent and Agent 2 via OpenSSL configuration
Weaknesses CWE-427
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Microsoft Windows
Zabbix Zabbix Zabbix-agent Zabbix-agent2 Zabbix Agentd
cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-02-26T17:48:21.215Z

Reserved: 2025-02-20T11:40:38.480Z

Link: CVE-2025-27237

cve-icon Vulnrichment

Updated: 2025-10-03T13:52:17.795Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-03T12:15:43.930

Modified: 2025-10-06T14:56:47.823

Link: CVE-2025-27237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-06T14:43:05Z

Weaknesses