Library Load Vulnerability in Zabbix Agent for AIX by Zabbix
CVE-2025-49642

5.8MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
1 December 2025

What is CVE-2025-49642?

A vulnerability exists in the Zabbix Agent for AIX systems that allows local users with write permissions to the /home/cecuser directory to hijack library loading processes. This could enable unauthorized actions by executing malicious code, potentially compromising system integrity. It highlights the importance of securing user permissions and monitoring file access within critical directories.

Affected Version(s)

Zabbix 6.0.0 <= 6.0.36

Zabbix 7.0.0 <= 7.0.5

Zabbix 7.2.0 < 7.2.1

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank José Pina Coelho for finding and reporting this issue.
.
CVE-2025-49642 : Library Load Vulnerability in Zabbix Agent for AIX by Zabbix