Improper Link Resolution Before File Access Vulnerability Affects Zscaler Client Connector on Windows
CVE-2023-41971

5.3MEDIUM

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
2 May 2024

What is CVE-2023-41971?

An Improper Link Resolution Before File Access vulnerability exists in Zscaler Client Connector for Windows, which may allow an attacker to overwrite system files. This specific flaw arises prior to version 3.7 of the Client Connector, potentially impacting the integrity and availability of affected systems. Proper patching and adherence to security configurations are critical to mitigating risks associated with this vulnerability.

Affected Version(s)

Client Connector Windows 0 < 3.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LMCO Red Team
.