VYPR
Medium severity6.4NVD Advisory· Published Aug 6, 2024· Updated Jun 17, 2026

CVE-2024-23460

CVE-2024-23460

Description

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

Affected products

3
  • cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*+ 2 more
    • cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*range: <4.2
    • (no CPE)range: <4.2
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.