Urgent.News

What's breaking now, across thousands of outlets.

Tech

Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

1. Basic Information Article Title : Vulnerability in Zabbix agent installer regarding incorrect file access permissions Publisher : JVN Publication Date : 2026-08-28 Original Source : JVN Related Information Sources : None Related Malware, Attack Groups, CVEs, and Products : CVE-2026-59781, Zabbix agent Severity : Medium 2. Summary In Zabbix agent versions prior to 7.0.24 and 7.4.8, incorrect…

Zabbix agent versions earlier than 7.0.24 and 7.4.8 have a vulnerability (CVE-2026-59781) that enables privilege escalation via DLL loading during installation. This flaw arises due to incorrect file access permissions, allowing a local low-privileged attacker to place a malicious DLL in a location searched by the installer. When an administrator runs the vulnerable installer, it loads the attacker's DLL, executing arbitrary code with administrator privileges.

The attacker's goal is to exploit the vulnerable installer and gain administrator privileges. The success of this attack depends on the attacker's ability to write to the DLL search path and an administrator running the vulnerable installer, which would allow the malicious DLL to take precedence over legitimate libraries. Although the vulnerability has a moderate severity rating (CVSS v4.0: 5.4, CVSS v3.1: 6.7), it requires local low privileges and user interaction. The vendor recommends updating to Zabbix agent 7.0.24, 7.4.8, or later to mitigate the risk.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Saturday 29 August →