LPE using arbitrary file delete with Symlinks
CVE-2023-28797

6.3MEDIUM

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
23 October 2023

What is CVE-2023-28797?

The Zscaler Client Connector for Windows prior to version 4.1 is susceptible to a vulnerability that allows a malicious user to manipulate a configuration file located within specific folders. By replacing this folder, the attacker could execute arbitrary code with elevated privileges, potentially compromising the security of the affected system.

Affected Version(s)

Client Connector 0 < 4.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rémi Orious
.