CVE-2007-6210

Zabbix <1.4.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6210. PoCs published by Bas van Schaik.

AI-analyzed exploit summary This exploit demonstrates a local privilege escalation (LPE) by leveraging improper setuid/setgid handling in the target software. It spawns a shell with elevated privileges by calling setuid/setgid on a user 'abi' and then executing /usr/bin/id to verify the privilege change.

Description

zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bas van Schaik · clocallinux
https://www.exploit-db.com/exploits/30839

This exploit demonstrates a local privilege escalation (LPE) by leveraging improper setuid/setgid handling in the target software. It spawns a shell with elevated privileges by calling setuid/setgid on a user 'abi' and then executing /usr/bin/id to verify the privilege change.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Unspecified software with improper setuid/setgid handling (likely a local binary or service)
No auth needed
Prerequisites: Presence of a vulnerable setuid/setgid binary · User 'abi' must exist on the system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1420
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27903
Various Sources x_refsource_confirm
http://www.zabbix.com/forum/showthread.php?t=8400
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27948
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27978
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26680

Scores

EPSS 0.0078
EPSS Percentile 51.0%

Details

CWE
CWE-16
Status published
Products (1)
zabbix/zabbix_agentd 1.1.4
Published Dec 04, 2007
Tracked Since Feb 18, 2026