CVE-2025-27237

Publication date 3 October 2025

Last updated 8 October 2025


Ubuntu priority

Description

In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.

Status

Package Ubuntu Release Status
zabbix 25.04 plucky
Not affected
24.04 LTS noble Not in release
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected