CVE-2025-27237
EUVD-2025-3253503.10.2025, 12:15
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.40 | CNA |
| zabbix | zabbix | 7.0.0 ≤ 𝑥 ≤ 7.0.17 | CNA |
| zabbix | zabbix | 7.2.0 ≤ 𝑥 ≤ 7.2.11 | CNA |
| zabbix | zabbix | 7.4.0 ≤ 𝑥 ≤ 7.4.1 | CNA |
Common Weakness Enumeration