VYPR

Client Connector

by Zscaler

CVEs (42)

  • CVE-2023-41969HigMar 26, 2024
    risk 0.47cvss 7.3epss 0.00

    An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.

  • CVE-2024-23483HigAug 6, 2024
    risk 0.46cvss 7.0epss 0.01

    An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.

  • CVE-2024-23459HigMay 2, 2024
    risk 0.46cvss 7.1epss 0.00

    An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.

  • CVE-2024-23482HigMar 26, 2024
    risk 0.46cvss 7.0epss 0.00

    The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.

  • CVE-2023-28796HigOct 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

  • CVE-2023-28805MedOct 23, 2023
    risk 0.44cvss 6.7epss 0.00

    An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105

  • CVE-2021-26736MedOct 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.

  • CVE-2021-26735MedOct 23, 2023
    risk 0.44cvss 6.7epss 0.00

    The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.

  • CVE-2024-23460MedAug 6, 2024
    risk 0.42cvss 6.4epss 0.00

    The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

  • CVE-2023-28798MedMay 2, 2024
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution.

  • CVE-2023-28797MedOct 23, 2023
    risk 0.41cvss 6.3epss 0.00

    Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.

  • CVE-2023-41970MedMay 2, 2024
    risk 0.39cvss 6.0epss 0.00

    An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Local Execution of Code.This issue affects Client Connector on Windows: before 4.1.0.62.

  • CVE-2023-28803MedOct 23, 2023
    risk 0.38cvss 5.9epss 0.00

    An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9.

  • CVE-2023-28806MedAug 6, 2024
    risk 0.37cvss 5.7epss 0.00

    An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.

  • CVE-2021-26737MedOct 23, 2023
    risk 0.36cvss 5.5epss 0.00

    The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.

  • CVE-2026-22569MedMar 31, 2026
    risk 0.35cvss 5.4epss 0.00

    An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

  • CVE-2023-41971MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.

  • CVE-2023-28802MedNov 21, 2023
    risk 0.32cvss 4.9epss 0.00

    An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149.

  • CVE-2021-26734MedOct 23, 2023
    risk 0.29cvss 4.4epss 0.00

    Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context.

  • CVE-2023-28794MedNov 6, 2023
    risk 0.28cvss 4.3epss 0.00

    Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.