Insecure DLL loading in Zabbix Agent and Zabbix Agent 2 - CVE-2025-27237
Published: October 6, 2025 / Updated: February 6, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads OpenSSL configuration file in an insecure manner from a path writable by low-privileged users. A local user can place a malicious file into the corresponding directory and escalate privileges on the system.
Affected software
Zabbix Agent 2
How to mitigate CVE-2025-27237
Zabbix Agent 2 - addressed in versions 6.0.41, 7.0.18, 7.2.12, 7.4.2