The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zscaler
Zscaler client Connector |
|
CPEs | cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:* | |
Vendors & Products |
Zscaler
Zscaler client Connector |
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: Zscaler
Published: 2024-08-06T15:29:26.050Z
Updated: 2024-08-06T20:06:58.896Z
Reserved: 2024-01-17T15:15:47.221Z
Link: CVE-2024-23460
Vulnrichment
Updated: 2024-08-06T20:06:50.947Z
NVD
Status : Analyzed
Published: 2024-08-06T16:15:47.460
Modified: 2024-08-07T21:29:01.067
Link: CVE-2024-23460
Redhat
No data.