CVE-2024-23460
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
Affected (1)
Products: Zscaler: Client Connector
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2 |
References (1)
Source: cve@zscaler.com
Vendor Advisory
Timeline
No history available yet.