CVE-2025-27233: Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27233?
The severity of CVE-2025-27233 is considered high due to the potential for NTLMv2 hash leakage from a Windows system.
How do I fix CVE-2025-27233?
To fix CVE-2025-27233, it is recommended to upgrade to the latest version of Zabbix Agent 2 where the vulnerability is patched.
What systems are affected by CVE-2025-27233?
CVE-2025-27233 affects Zabbix Agent 2 versions starting from 6.0 and can impact Windows systems specifically.
What can attackers do with CVE-2025-27233?
Attackers exploiting CVE-2025-27233 can inject unexpected arguments into the smartctl command, potentially leaking sensitive information like NTLMv2 hashes.
Is there a workaround for CVE-2025-27233?
While upgrading is the best course of action, disabling the smartctl plugin may serve as a temporary workaround for CVE-2025-27233.