A critical security vulnerability, tracked as CVE-2025-27237, has been identified in Zabbix Agent and Agent2 for Windows, allowing local users to escalate their privileges to SYSTEM level. The flaw arises from the way affected versions of the Zabbix Agent handle the OpenSSL configuration file, which is loaded from a directory that can be modified by non-administrative users. This misconfiguration enables attackers with local access to tamper with the OpenSSL configuration file and inject a malicious DLL. Upon the next restart of the Zabbix service or the system, the injected DLL is executed with SYSTEM privileges, granting the attacker full control over the affected machine. The vulnerability impacts Zabbix Agent and Agent2 versions 6.0.0 through 6.0.40, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, and 7.4.0 through 7.4.1 on Windows platforms. Security advisories have assigned this issue a CVSS 4.0 score of 7.3, indicating a high severity level. The scoring vector highlights the low attack complexity and the significant impact on confidentiality, integrity, and availability. The vulnerability was responsibly disclosed, and Zabbix has issued guidance for affected users. Exploitation requires local access, but the risk is substantial in environments where multiple users have access to the same Windows system. The attack does not require user interaction, making it particularly dangerous in shared or multi-user environments. Organizations using vulnerable versions are urged to update their Zabbix Agent installations or apply recommended mitigations immediately. The flaw underscores the importance of secure configuration file handling and proper privilege separation in software running with elevated permissions. Security researchers have demonstrated the exploitability of the issue, emphasizing the need for prompt remediation. The vulnerability does not affect Zabbix Agents running on non-Windows platforms. Zabbix is a widely used open-source network monitoring solution, and compromise of its agent can lead to broader network security risks. Administrators should review their deployment for affected versions and monitor for signs of unauthorized privilege escalation. The incident highlights ongoing challenges in securing third-party dependencies and configuration management in enterprise environments.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.