Impact
A buffer overflow flaw in the Zscaler Client Connector application on Windows can be triggered remotely, leading to application termination and potentially a kernel‑level crash. The vulnerability arose from an unchecked write beyond the bounds of a buffer, which is consistent with CWE‑229 and can disrupt both local and system processes.
Affected Systems
All Windows installations of the Zscaler Client Connector appear to be vulnerable, as the vendor has not specified affected version ranges in the advisory. Until a patch is applied, any currently deployed instance on a Windows host should be considered at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA KEV, but the lack of a publicly known exploit does not diminish the need for remediation. Based on the description, it is inferred that attackers can deliver malicious data to the client service over the network, potentially exploiting the overflow to crash the local application or, due to the client’s elevated privileges, to cause a kernel‑level denial of service.
OpenCVE Enrichment