#VU116619 Insecure DLL loading in Zabbix Agent and Zabbix Agent 2 - CVE-2025-27237
Published: October 6, 2025 / Updated: February 6, 2026
Zabbix Agent
Zabbix Agent 2
Zabbix
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads OpenSSL configuration file in an insecure manner from a path writable by low-privileged users. A local user can place a malicious file into the corresponding directory and escalate privileges on the system.