discovered 03 Aug 2026
CVE-2025-27237
→ View on GitHubCVE-2025-27237 is a local privilege escalation vulnerability affecting the Zabbix Agent for Windows, which arises from OpenSSL configuration file hijacking due to hardcoded paths accessible to low-privileged users. This tool provides scripts and proof-of-concept (PoC) implementations to analyze affected Zabbix binaries, compile malicious DLLs, and facilitate exploitation in vulnerable systems, while also offering methods for detection and remediation. Key features include binary analysis tools and detailed documentation for ensuring system security against this identified vulnerability.