DLL Sideloading Vulnerability in Zabbix Agent for Windows
CVE-2026-59781
What is CVE-2026-59781?
The Zabbix Agent for Windows has a vulnerability that occurs when it is installed in a custom directory without sufficient access permissions. This lack of verification allows unauthorized users to manipulate the installation directory, potentially leading to DLL sideloading attacks. If a malicious DLL is placed in the directory, it can be executed by the application, compromising system integrity. The updated installer now includes security measures to validate directory permissions and prompts for user confirmation when attempting to install in unsecured locations, thereby enhancing the overall security posture without disrupting existing user deployments.
Affected Version(s)
Zabbix 7.4.0 <= 7.4.12
Zabbix 7.0.0 <= 7.0.28
Zabbix 6.0.0 <= 6.0.47
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
