LPE using arbitrary file delete with Symlinks
CVE-2023-28797
6.3MEDIUM
What is CVE-2023-28797?
The Zscaler Client Connector for Windows prior to version 4.1 is susceptible to a vulnerability that allows a malicious user to manipulate a configuration file located within specific folders. By replacing this folder, the attacker could execute arbitrary code with elevated privileges, potentially compromising the security of the affected system.
Affected Version(s)
Client Connector 0 < 4.1