Privilege Escalation Vulnerability in Zscaler Client Connector for Mac
CVE-2024-31127

7.3HIGH

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
4 June 2025

What is CVE-2024-31127?

An improper verification of a loaded library in the Zscaler Client Connector on Mac versions prior to 4.2.0.241 allows a local attacker to exploit this vulnerability. By gaining elevated privileges, the attacker may execute arbitrary code or gain unauthorized access to sensitive information, potentially compromising the security of the affected system.

Affected Version(s)

Client Connector MacOS 0 < 4.2.0.241

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Max Keasley
.
CVE-2024-31127 : Privilege Escalation Vulnerability in Zscaler Client Connector for Mac