CVE-2025-27233 Details
Description
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
An argument injection vulnerability has been identified in the smartctl plugin of Zabbix Agent 2, affecting versions 6.0.0 through 6.0.39, 7.0.0 through 7.0.10, and 7.2.0 through 7.2.4. The vulnerability arises because the plugin fails to properly sanitize parameters for the smart.disk.get command, allowing attackers to inject unexpected arguments. This exploitation could lead to the leakage of NTLMv2 hashes from Windows systems.
Users can update Zabbix Agent 2 to version 6.0.40, 7.0.11, or 7.2.5, depending on their current version. Alternatively, smartctl can be removed or strict validation of item key parameters can be implemented using AllowKey/DenyKey.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 12, 2025CISA-ADP
Assessed Sep 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.zabbix.com/browse/ZBX-26987 | [email protected] | AdvisoryIssue TrackingRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zabbix Agent 2 | >= 6.0.0, <= 6.0.39 (semver) >= 7.0.0, <= 7.0.10 (semver) >= 7.2.0, <= 7.2.4 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2025 | New CVE Received | [email protected] |
Volerion