Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
Zabbix provides users with a JavaScript scripting execution environment (e.g., in preprocessing or alertscripts). Due to insufficient input validation, a user is able to directly manipulate memory pointers (memory pointers) of the running JavaScript engine. In accordance with the CWE-822 classification (Untrusted Pointer Dereference), dereferencing an untrusted pointer can cause unpredictable process behavior — from crashes to potential arbitrary code execution. The attack does not require victim interaction or special privileges beyond basic system access, and its effects extend beyond the context of the attacked component (Scope: Changed).
An attacker can cause unavailability of the monitoring system (DoS), and potentially also gain unauthorized access to data or execute arbitrary code in the context of the Zabbix process. The scope of impact includes confidentiality, integrity, and availability of the protected infrastructure.
Patches available from the vendor should be applied in accordance with the references — detailed information about patched versions can be found at https://support.zabbix.com/browse/ZBX-25018. Debian LTS distribution users should update packages in accordance with the announcement published on the debian-lts-announce mailing list (October 2024). Additionally, it is recommended to restrict permissions to create and edit JavaScript scripts only to trusted users.
Zabbix products (Zabbix Server / Zabbix Proxy / Zabbix Agent) — specific versions indicated in vendor references (report ZBX-25018); the vulnerability also affects Zabbix packages available in Debian LTS.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:HZabbix
APPZabbix7.0.06.0.0 – 6.0.306.4.0 – 6.4.15
Related vulnerabilities
Zabbix SAML SSO — privilege escalation do konta administratora
SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień
Zabbix: niekodowane nagłówki HTTP umożliwiają dostęp do ukrytych właściwości obiektów
Zabbix: RCE przez brak escapowania parametrów skryptu Ping
Zabbix Server — time-based blind SQL injection przez pole clientip