Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

Zabbix agent CVE-2026-59781:安装过程中通过 DLL 加载实现权限提升

1. Basic Information

1. 基本信息

Article Title: Vulnerability in Zabbix agent installer regarding incorrect file access permissions 文章标题: Zabbix agent 安装程序中关于文件访问权限不当的漏洞

Publisher: JVN 发布者: JVN

Publication Date: 2026-08-28 发布日期: 2026-08-28

Original Source: JVN 原始来源: JVN

Related Information Sources: None 相关信息来源:

Related Malware, Attack Groups, CVEs, and Products: CVE-2026-59781, Zabbix agent 相关恶意软件、攻击组织、CVE 及产品: CVE-2026-59781, Zabbix agent

Severity: Medium 严重程度: 中等


2. Summary

2. 摘要

In Zabbix agent versions prior to 7.0.24 and 7.4.8, incorrect file access permissions during installation allow a local low-privileged attacker to load a malicious DLL and execute arbitrary code with administrator privileges. 在 7.0.24 和 7.4.8 版本之前的 Zabbix agent 中,安装过程中不正确的文件访问权限允许本地低权限攻击者加载恶意 DLL,并以管理员权限执行任意代码。


3. Attack Flow

3. 攻击流程

Attack Steps: 攻击步骤:

  1. A low-privileged attacker places a malicious DLL in a location searched by the installer.
  2. 低权限攻击者将恶意 DLL 放置在安装程序搜索的路径中。
  3. An administrator runs the vulnerable installer.
  4. 管理员运行存在漏洞的安装程序。
  5. The installer loads the attacker’s DLL.
  6. 安装程序加载攻击者的 DLL。
  7. The DLL code runs with administrator privileges.
  8. DLL 代码以管理员权限运行。

4. Attacker Position and Execution Location

4. 攻击者位置与执行位置

An attacker who has access to the target product and can exploit vulnerable features or improper permission boundaries. Operates under the application or escalated privileges after success. 攻击者能够访问目标产品,并利用易受攻击的功能或不当的权限边界。成功后在应用程序下运行或获得提升后的权限。


5. Visibility for Victims and Administrators

5. 受害者与管理员的可见性

Victims: Hard to detect from on-screen signs alone, as it looks like normal operations or occurs without user interaction. 受害者: 仅从屏幕迹象难以察觉,因为它看起来像正常操作,或者在没有用户交互的情况下发生。

Administrators: Events where the installer loads a DLL from a user-writable location. Suspicious child processes, services, tasks, or user creation originating from the installer. Outbound traffic to unknown destinations from endpoints immediately after an update. 管理员: 安装程序从用户可写位置加载 DLL 的事件。源自安装程序的异常子进程、服务、任务或用户创建。更新后终端立即向未知目的地发送的出站流量。


6. Success and Failure Conditions

6. 成功与失败条件

Success Conditions: The attacker can write to the DLL search path. An administrator runs the vulnerable installer. The malicious DLL takes precedence over legitimate libraries. 成功条件: 攻击者可以写入 DLL 搜索路径。管理员运行了易受攻击的安装程序。恶意 DLL 优先于合法库被加载。

Failure Conditions / Risk Mitigation: Update to Zabbix agent 7.0.24, 7.4.8, or later. Run the installer from a dedicated directory writable only by administrators. Minimize ACLs on distribution shares and temporary directories. 失败条件 / 风险缓解: 更新至 Zabbix agent 7.0.24、7.4.8 或更高版本。从仅管理员可写的专用目录运行安装程序。最小化分发共享和临时目录的 ACL。


7. What Happens Upon Success

7. 成功后的后果

Privilege escalation from a low-privileged user to administrator privileges. Persistence, credential theft, and monitoring disruption on the monitored endpoint. 从低权限用户提升至管理员权限。在受监控终端上实现持久化、凭据窃取及监控中断。


8. Observable Logs

8. 可观测日志

  • Email: None. (邮件:无)
  • Proxy/SWG/DNS: Events where the installer loads a DLL from a user-writable location. (代理/SWG/DNS:安装程序从用户可写位置加载 DLL 的事件)
  • Endpoint/EDR: Suspicious child processes, services, tasks, or user creation originating from the installer. (终端/EDR:源自安装程序的异常子进程、服务、任务或用户创建)
  • Identity/IdP: Outbound traffic to unknown destinations from endpoints immediately after an update. (身份/IdP:更新后终端立即向未知目的地发送的出站流量)
  • SaaS/Cloud: Check WAF, load balancers, and audit logs during cloud operations. (SaaS/云:检查云操作期间的 WAF、负载均衡器和审计日志)
  • Network: Check for outbound traffic to unknown destinations after success. (网络:检查成功后是否存在向未知目的地的出站流量)

9. Attack Success Determination

9. 攻击成功判定

  • Attack Attempt Observed (Success Unconfirmed): Contact with the target is confirmed, but unauthorized operations or code execution are unconfirmed. (观察到攻击尝试(成功未确认):确认与目标接触,但未确认未经授权的操作或代码执行)
  • User Action Confirmed: An administrator ran the vulnerable installer. (用户操作已确认:管理员运行了易受攻击的安装程序)
  • Initial Execution Confirmed: Unauthorized responses, processing, or suspicious child processes are confirmed. (初始执行已确认:确认存在未经授权的响应、处理或异常子进程)
  • Data Theft or Session Compromise Confirmed: Unauthorized information retrieval, credential access, or transmission is confirmed. (数据窃取或会话泄露已确认:确认存在未经授权的信息检索、凭据访问或传输)
  • Subsequent Compromise Confirmed: Additional payloads, persistence, tampering, deletion, or lateral movement is confirmed. (后续入侵已确认:确认存在额外的载荷、持久化、篡改、删除或横向移动)

10. Investigation Playbook

10. 调查手册

  • Trigger: Detection of Zabbix agent vulnerability exploitation or abnormal behavior. (触发:检测到 Zabbix agent 漏洞利用或异常行为)
  • Initial Verification: Check version, exposure scope, patch status, initial anomaly time, and source. Preserve HTTP, application, and audit logs. (初步验证:检查版本、暴露范围、补丁状态、初始异常时间和来源。保留 HTTP、应用程序和审计日志)
  • Endpoint: Suspicious child processes, services, tasks, or user creation originating from the installer. (终端:源自安装程序的异常子进程、服务、任务或用户创建)
  • Authentication & Cloud: Outbound traffic to unknown destinations from endpoints immediately after an update. (身份验证与云:更新后终端立即向未知目的地发送的出站流量)
  • Subsequent Operations: Investigate additional files, outbound traffic, credential access, and impact on other assets. (后续操作:调查额外文件、出站流量、凭据访问以及对其他资产的影响)
  • Containment: Update to Zabbix agent 7.0.24, 7.4.8, or later. Run the installer from a dedicated directory writable only by administrators. Minimize ACLs on distribution shares and temporary directories. If a compromise is confirmed, isolate the target and revoke related credentials and sessions. (遏制:更新至 Zabbix agent 7.0.24、7.4.8 或更高版本。从仅管理员可写的专用目录运行安装程序。最小化分发共享和临时目录的 ACL。如果确认被入侵,隔离目标并撤销相关凭据和会话)
  • Determination Categories: Distinguish between contact, prerequisites met, initial success, information compromise, and subsequent compromise. (判定类别:区分接触、满足先决条件、初步成功、信息泄露和后续入侵)

11. Defense and Detection Ideas

11. 防御与检测思路

  • Single Event: Events where the installer loads a DLL from a user-writable location. (单次事件:安装程序从用户可写位置加载 DLL 的事件)
  • Time-Series Correlation: External request or operation -> vulnerable feature -> privilege escalation from low-privileged user to administrator. Correlate with subsequent behavior. (时间序列关联:外部请求或操作 -> 易受攻击功能 -> 从低权限用户提升至管理员权限。与后续行为关联)
  • Threat Hunting: Events where the installer loads a DLL from a user-writable location. Suspicious child processes, services, tasks, or user creation originating from the installer. Outbound traffic to unknown destinations from endpoints immediately after an update. (威胁狩猎:安装程序从用户可写位置加载 DLL 的事件。源自安装程序的异常子进程、服务、任务或用户创建。更新后终端立即向未知目的地发送的出站流量)
  • Log Gaps: Success stages cannot be determined if HTTP, application, process, identity, and network timestamps cannot be correlated. (日志缺口:如果无法关联 HTTP、应用程序、进程、身份和网络时间戳,则无法确定成功阶段)
  • Priority Mitigations: Update to Zabbix agent 7.0.24, 7.4.8, or later. Run the installer from a dedicated directory writable only by administrators. Minimize ACLs on distribution shares and temporary directories. (优先缓解措施:更新至 Zabbix agent 7.0.24、7.4.8 或更高版本。从仅管理员可写的专用目录运行安装程序。最小化分发共享和临时目录的 ACL)

12. Facts / Inference / Hypothesis

12. 事实 / 推理 / 假设

  • Facts: Zabbix agent versions prior to 7.0.24 and 7.4.8 are affected. Incorrect file access permissions in the installer allow malicious DLLs to be executed with administrator privileges. CVSS v4.0 is 5.4, and CVSS v3.1 is 6.7, requiring local low privileges and user interaction. The vendor recommends updating to fixed versions. (事实:7.0.24 和 7.4.8 版本之前的 Zabbix agent 受影响。安装程序中不正确的文件访问权限允许恶意 DLL 以管理员权限执行。CVSS v4.0 为 5.4,CVSS v3.1 为 6.7,需要本地低权限和用户交互。厂商建议更新至修复版本)
  • Inference: It is necessary to correlate requests, application processing, unauthorized operations, and subsequent behavior, rather than relying on individual IOCs alone. (推理:有必要关联请求、应用程序处理、未经授权的操作和后续行为,而不是仅依赖单一的 IOC)
  • Hypothesis: The presence of actual exploitation or additional damage cannot be determined from public information alone. (假设:仅凭公开信息无法确定是否存在实际利用或额外损害)

13. MITRE ATT&CK Mapping

13. MITRE ATT&CK 映射

  • T1574.002 Hijack Execution Flow: DLL Side-Loading (High): In Zabbix agent versions prior to 7.0.24 and 7.4.8, incorrect file access permissions during installation allow a local low-privileged attacker…
  • T1574.002 劫持执行流:DLL 侧加载(高): 在 7.0.24 和 7.4.8 版本之前的 Zabbix agent 中,安装过程中不正确的文件访问权限允许本地低权限攻击者……