Home
HIGH: 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unknown
6.0.0 (git)
affected
7.0.0 (git)
affected
7.2.0 (git)
affected
7.4.0 (git)
affected
Description
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
Problem types
CWE-427: Uncontrolled Search Path Element
Product status
6.0.0 (git)
7.0.0 (git)
7.2.0 (git)
7.4.0 (git)
Credits
Zabbix wants to thank himbeer for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-27061