CVE-2025-27233
EUVD-2025-2903512.09.2025, 11:15
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.39 | CNA |
| zabbix | zabbix | 7.0.0 ≤ 𝑥 ≤ 7.0.10 | CNA |
| zabbix | zabbix | 7.2.0 ≤ 𝑥 ≤ 7.2.4 | CNA |
Debian Releases