Zabbix executes commands by design, to collect data and to react to problems, so for an attacker with sufficient access it is a code-execution platform. There are several distinct primitives. Item keys such as system.run[] execute on a Zabbix agent when the item is evaluated. Global scripts and alert (action) scripts run commands on the Zabbix server (or a selected agent) when triggered. The Zabbix agent on 10050 directly executes system.run where remote commands are permitted, reachable without the server. SQL injection in the frontend extracts sessions and credentials and chains to the above. And the server and frontend have had their own remote-code-execution vulnerabilities. The server and agents run these commands as their service accounts (often zabbix, sometimes more), so execution is a foothold on the monitoring host and, through agents, on monitored hosts.
Subtopics#
- Item command execution: system.run and command items on agents.
- Global and alert scripts: scripts that run on the server.
- Agent remote commands: direct execution against the agent on 10050.
- SQL injection to RCE: frontend SQLi and its chains.
- Known server exploits: the recurring server/frontend RCE.