Code execution

Zabbix executes commands by design, to collect data and to react to problems, so for an attacker with sufficient access it is a code-execution platform. There are several distinct primitives. Item keys such as system.run[] execute on a Zabbix agent when the item is evaluated. Global scripts and alert (action) scripts run commands on the Zabbix server (or a selected agent) when triggered. The Zabbix agent on 10050 directly executes system.run where remote commands are permitted, reachable without the server. SQL injection in the frontend extracts sessions and credentials and chains to the above. And the server and frontend have had their own remote-code-execution vulnerabilities. The server and agents run these commands as their service accounts (often zabbix, sometimes more), so execution is a foothold on the monitoring host and, through agents, on monitored hosts.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more