Missing reparse point check in Client Connector could lead to local privilege escalation
CVE-2024-23458

7.8HIGH

Key Information:

Vendor
Zscaler
Status
Client Connector
Vendor
CVE Published:
6 August 2024

Summary

A local privilege escalation vulnerability exists in the Zscaler Client Connector on Windows due to a missing reparse point check while copying individual autoupdater log files. This security flaw could enable an attacker to exploit the system, allowing them to gain elevated privileges. It is essential for users running versions prior to 4.2.0.190 to review the applicable updates and apply necessary patches to mitigate this risk.

Affected Version(s)

Client Connector Windows 0 < 4.2.0.190

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Equinor Red Team
.