A critical security vulnerability has been discovered in Zabbix Agent and Agent 2 for Windows, allowing attackers with local access to escalate their privileges via DLL injection attacks.

The vulnerability, tracked as CVE-2025-27237 and rated CVSS 7.3 (High), affects multiple versions of the popular network monitoring solution. Zabbix has released security updates.
The issue arises from improper handling of OpenSSL configuration files in Windows environments, where the configuration file is loaded from a path that can be modified by users with low privileges. This design flaw creates an attack point for malicious users who can inject dynamic link libraries (DLLs) to gain more system privileges.
See also: PoC exploit and details of Chrome RCE vulnerability released
Zabbix Agent and Agent 2: Privilege escalation
The vulnerability is located in the way Zabbix Agent and Agent 2 process OpenSSL configuration files on Windows systems. The agents load the OpenSSL configuration from a file path that has inadequate access controls, allowing users with limited privileges to modify the configuration content.
The attack requires local access to the system and involves modifying the OpenSSL configuration file to point to a malicious DLL that is loaded during agent startup or the system reboot process.

The vulnerability affects a wide range of Zabbix versions, including versions 6.0.0 to 6.0.40, 7.0.0 to 7.0.17, 7.2.0 to 7.2.11, and 7.4.0 to 7.4.1.
See also: PoC Exploit published for zero-day in Oracle E-Business Suite
Prerequisites for the attack: attackers need existing access to the Windows system with Zabbix Agent installed and the malicious setting takes effect only after the Zabbix Agent service or the system is restarted.
Security researcher himbeer discovered this vulnerability and reported it through Zabbix's bug bounty program on HackerOne.
The DLL injection technique exploits the trust relationship between the Zabbix Agent service and the OpenSSL library, allowing attackers to execute arbitrary code with the elevated privileges of the agent process.

Protection
Zabbix has released security updates to all affected product lines to address this privilege escalation vulnerability. System administrators should immediately update their Zabbix Agent installations. The company does not provide any other solutions for this vulnerability, making security updates the primary mitigation strategy.
See also: PoC Exploit released for Sudo vulnerability that allows Root access
Organizations using Zabbix monitoring infrastructure should prioritize these updates , especially in environments where many users have local access to the system or where monitoring agents run with elevated privileges. Given the widespread deployment of Zabbix monitoring solutions in enterprise environments, this security vulnerability could potentially affect thousands of Windows-based installations worldwide.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
