Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown

CVE-2024-23459

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.
0
Attacker Value
Unknown

CVE-2023-41971

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.
0
Attacker Value
Unknown

CVE-2023-41970

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Local Execution of Code.This issue affects Client Connector on Windows: before 4.1.0.62.
0
Attacker Value
Unknown

CVE-2023-28798

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-23480

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
0
Attacker Value
Unknown

CVE-2024-23457

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209
0
Attacker Value
Unknown

CVE-2024-23463

Disclosure Date: April 30, 2024 (last updated May 01, 2024)
Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1
0
Attacker Value
Unknown

CVE-2024-23482

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.
0
Attacker Value
Unknown

CVE-2023-41973

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.
0
Attacker Value
Unknown

CVE-2023-41972

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.
0