Client IPC validation bypass
CVE-2023-28795

7.8HIGH

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
23 October 2023

What is CVE-2023-28795?

The Zscaler Client Connector on Linux has an Origin Validation Error vulnerability that allows for code inclusion within an existing process. This issue potentially affects systems running versions prior to 1.3.1.6, posing security risks to the integrity of user settings and data. It is crucial for users to upgrade to the latest version to mitigate potential exploitation and safeguard their environments.

Affected Version(s)

Client Connector 0 < 1.3.1.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paul Gerste, SonarSource
.