Arbitrary Code Execution Vulnerability in Zscaler Client Connector on MacOS
CVE-2024-23460

7.8HIGH

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
6 August 2024

What is CVE-2024-23460?

The Zscaler Client Connector for MacOS is susceptible to a security vulnerability wherein the Updater process fails to properly validate the digital signature of the installer prior to execution. This oversight allows for the potential execution of arbitrary code on affected systems running versions earlier than 4.2. Users of the Zscaler Client Connector should be aware of this risk and consider upgrading to the latest versions to mitigate situations that could lead to potential exploits.

Affected Version(s)

Client Connector MacOS 0 < 4.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LMCO Red Team
.