PT-2025-48443 · Zabbix+2 · Zabbix Agent+2

Published

2025-12-01

·

Updated

2026-02-09

·

CVE-2025-49642

CVSS v2.0

6.4

Medium

VectorAV:L/AC:L/Au:S/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zabbix Agent versions (affected versions not specified)
Description The Zabbix Agent builds on AIX are susceptible to a library loading hijacking issue. Local users possessing write access to the /home/cecuser directory can exploit this to hijack the library loading process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Weakness Enumeration

Related Identifiers

ALT-PU-2025-15932
BDU:2025-15875
CVE-2025-49642

Affected Products

Alt Linux
Red Os
Zabbix Agent