Client Connector
by Zscaler
CVEs (42)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11633 | Cri | 0.64 | 9.8 | 0.02 | Jul 15, 2021 | The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges. | ||
| CVE-2024-23463 | Hig | 0.57 | 8.8 | 0.00 | Apr 30, 2024 | Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1 | ||
| CVE-2023-28804 | Hig | 0.53 | 8.2 | 0.00 | Oct 23, 2023 | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105 | ||
| CVE-2023-28800 | Hig | 0.53 | 8.1 | 0.01 | Jun 22, 2023 | When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login. | ||
| CVE-2023-28799 | Hig | 0.53 | 8.2 | 0.00 | Jun 22, 2023 | A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain. | ||
| CVE-2024-23456 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2024 | Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled. | ||
| CVE-2024-23457 | Hig | 0.51 | 7.8 | 0.00 | May 1, 2024 | The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209 | ||
| CVE-2023-28795 | Hig | 0.51 | 7.8 | 0.00 | Oct 23, 2023 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | ||
| CVE-2023-28793 | Hig | 0.51 | 7.8 | 0.00 | Oct 23, 2023 | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | ||
| CVE-2021-26738 | Hig | 0.51 | 7.8 | 0.00 | Oct 23, 2023 | Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges. | ||
| CVE-2020-11634 | Hig | 0.51 | 7.8 | 0.00 | Jul 15, 2021 | The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context. | ||
| CVE-2020-11632 | Hig | 0.51 | 7.8 | 0.00 | Jul 15, 2021 | The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges. | ||
| CVE-2020-11635 | Hig | 0.51 | 7.8 | 0.00 | Feb 16, 2021 | The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges. | ||
| CVE-2024-3661 | Hig | 0.50 | 7.6 | 0.04 | May 6, 2024 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt,… | ||
| CVE-2024-23480 | Hig | 0.49 | 7.5 | 0.00 | May 1, 2024 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2. | ||
| CVE-2024-31127 | Hig | 0.47 | 7.3 | 0.00 | Jun 4, 2025 | An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges. | ||
| CVE-2024-23464 | Hig | 0.47 | 7.2 | 0.00 | Aug 6, 2024 | In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1 | ||
| CVE-2024-23458 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2024 | While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190. | ||
| CVE-2023-41973 | Hig | 0.47 | 7.3 | 0.00 | Mar 26, 2024 | ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later. | ||
| CVE-2023-41972 | Hig | 0.47 | 7.3 | 0.00 | Mar 26, 2024 | In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later. |
- risk 0.64cvss 9.8epss 0.02
The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.
- risk 0.57cvss 8.8epss 0.00
Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1
- risk 0.53cvss 8.2epss 0.00
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105
- risk 0.53cvss 8.1epss 0.01
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
- risk 0.53cvss 8.2epss 0.00
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
- risk 0.51cvss 7.8epss 0.00
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.
- risk 0.51cvss 7.8epss 0.00
The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209
- risk 0.51cvss 7.8epss 0.00
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- risk 0.51cvss 7.8epss 0.00
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- risk 0.51cvss 7.8epss 0.00
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.
- risk 0.51cvss 7.8epss 0.00
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.
- risk 0.51cvss 7.8epss 0.00
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
- risk 0.51cvss 7.8epss 0.00
The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.
- risk 0.50cvss 7.6epss 0.04
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt,…
- risk 0.49cvss 7.5epss 0.00
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
- risk 0.47cvss 7.3epss 0.00
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
- risk 0.47cvss 7.2epss 0.00
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1
- risk 0.47cvss 7.3epss 0.00
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.
- risk 0.47cvss 7.3epss 0.00
ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.
- risk 0.47cvss 7.3epss 0.00
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.
Page 1 of 3