VYPR

Zabbix Agentd

by Zabbix

CVEs (9)

  • CVE-2026-59781HigAug 18, 2026
    risk 0.51cvss 7.8epss 0.00

    When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a…

  • CVE-2025-27237HigOct 3, 2025
    risk 0.47cvss —epss 0.00

    In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.

  • CVE-2022-43516MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)

  • CVE-2024-22121MedAug 12, 2024
    risk 0.40cvss 6.1epss 0.00

    A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

  • CVE-2025-49642MedDec 1, 2025
    risk 0.38cvss —epss 0.00

    Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.

  • CVE-2025-27233MedSep 12, 2025
    risk 0.37cvss —epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.

  • CVE-2023-32728MedDec 18, 2023
    risk 0.30cvss 4.6epss 0.01

    The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.

  • CVE-2008-1353Mar 17, 2008
    risk 0.03cvss —epss 0.06

    zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

  • CVE-2007-6210Dec 4, 2007
    risk 0.03cvss —epss 0.01

    zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.