Description
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
Problem types
CWE-427: Uncontrolled Search Path Element
Product status
6.0.0
7.0.0
7.2.0
7.4.0
Credits
Zabbix wants to thank himbeer for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-27061