📦 Client Connector

by Zscaler

🔍 What is Client Connector?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-11633

CRITICAL CVSS 9.8 Jul 15, 2021

A stack-based buffer overflow vulnerability in Zscaler Client Connector for Windows allows remote code execution with SYSTEM privileges when connecting to misconfigured TLS servers. This affects Windo...

CVE-2024-23456

HIGH CVSS 7.8 Aug 6, 2024

This vulnerability allows attackers to disable anti-tampering protection in Zscaler Client Connector without proper signature validation. This affects Windows users running Zscaler Client Connector ve...

CVE-2024-23464

HIGH CVSS 7.2 Aug 6, 2024

This vulnerability allows administrators with PowerShell access to disable Zscaler Internet Access (ZIA) protection on Windows systems. It affects organizations using Zscaler Client Connector on Windo...

CVE-2024-23459

HIGH CVSS 7.1 May 2, 2024

This vulnerability allows an attacker to exploit improper link resolution in Zscaler Client Connector on macOS, enabling them to overwrite system files. This affects all macOS users running Zscaler Cl...

CVE-2024-23457

HIGH CVSS 7.8 May 1, 2024

This vulnerability allows attackers to disable the anti-tampering protection in Zscaler Client Connector when an uninstall password is configured. This affects Windows systems running Zscaler Client C...

CVE-2024-23463

HIGH CVSS 8.8 Apr 30, 2024

This vulnerability allows attackers to bypass anti-tampering protection in Zscaler Client Connector when the Repair App functionality is used. It affects Windows users running Zscaler Client Connector...

CVE-2024-23482

HIGH CVSS 7.0 Mar 26, 2024

This CVE describes a local privilege escalation vulnerability in ZScaler's ZScalerService process on macOS. An attacker with local access can exploit this to gain elevated privileges on the system. On...

CVE-2023-41969

HIGH CVSS 7.3 Mar 26, 2024

This vulnerability in ZSATrayManager allows unprivileged users to delete arbitrary files by exploiting inadequate protection of temporary encrypted ZApp issue reporting files. It affects Zscaler Clien...

CVE-2023-41973

HIGH CVSS 7.3 Mar 26, 2024

This vulnerability in Zscaler Client Connector (ZSATray) allows path traversal attacks by improperly validating the 'previousInstallerName' parameter. Attackers could execute arbitrary code by manipul...

CVE-2021-26738

HIGH CVSS 7.8 Oct 23, 2023

This vulnerability in Zscaler Client Connector for macOS allows local attackers to execute arbitrary code with root privileges by exploiting an unquoted search path in the PATH variable. It affects ma...

CVE-2023-28795

HIGH CVSS 7.8 Oct 23, 2023

This CVE describes an origin validation error in Zscaler Client Connector for Linux that allows attackers to inject code into existing processes. The vulnerability affects Linux systems running Zscale...

CVE-2023-28804

HIGH CVSS 8.2 Oct 23, 2023

This vulnerability allows attackers to replace binaries in Zscaler Client Connector on Linux due to improper cryptographic signature verification. It affects Linux users running Zscaler Client Connect...

CVE-2023-28799

HIGH CVSS 8.2 Jun 22, 2023

This vulnerability allows an attacker to inject a malicious domain into a URL parameter during login, causing post-authentication redirection to the attacker's domain with the user's authorization tok...

CVE-2020-11632

HIGH CVSS 7.8 Jul 15, 2021

This vulnerability in Zscaler Client Connector allows a local attacker to execute arbitrary code with SYSTEM privileges by exploiting an unquoted service path. It affects Windows systems running Zscal...

CVE-2024-23460

MEDIUM CVSS 6.4 Aug 6, 2024

This vulnerability allows local attackers to execute arbitrary code on macOS systems by exploiting the Zscaler Updater's failure to validate digital signatures before executing installers. It affects ...

CVE-2023-41971

MEDIUM CVSS 5.3 May 2, 2024

This vulnerability in Zscaler Client Connector on Windows allows attackers to overwrite system files through improper link resolution. It affects all Windows systems running Zscaler Client Connector v...

CVE-2023-28798

MEDIUM CVSS 6.5 May 2, 2024

This vulnerability allows an attacker to write data beyond allocated heap memory boundaries in the pacparser library used by Zscaler Client Connector on macOS. Successful exploitation could lead to ar...

CVE-2024-23462

LOW CVSS 3.3 May 2, 2024

An improper validation vulnerability in Zscaler Client Connector on macOS allows attackers to cause denial of service by crashing the client binary, which removes VPN and security functionality. This ...