Impact
The reported flaws in Zscaler Client Connector allow a local, unprivileged user to obtain elevated privileges, enabling the execution of arbitrary code with administrative rights. This results in a potential compromise of confidentiality, integrity, and availability, giving attackers full control over the affected system. The vulnerabilities are mapped to CWE-280, indicating an improper permission assignment issue.
Affected Systems
The sole vendor/product impacted is Zscaler Client Connector. All installed instances that have not yet been updated to the latest release are susceptible, as the vulnerability list does not specify precise version ranges. Administrators should assume that every current release may be affected until an official patch is released.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity flaw. The EPSS score is unavailable and the vulnerability is not included in CISA’s KEV catalog, which suggests there is no confirmed exploitation in the wild yet. The attack vector is local. An attacker must have local access to the host, such as physical presence or a user account with read access to the Client Connector process, to exploit the flaw. Once the privilege escalation succeeds, the attacker can execute any code on the machine, including installing malware or extracting sensitive data.
OpenCVE Enrichment