High severity7.8NVD Advisory· Published Jul 15, 2021· Updated Jun 17, 2026
CVE-2020-11632
CVE-2020-11632
Description
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
Affected products
3cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:windows:*:*range: <2.1.2.150
- (no CPE)
- Range: <2.1.2.150
Patches
Vulnerability mechanics
References
1- help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2020nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.