The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
References
Configurations
History
No history.
Information
Published : 2024-08-06 16:15
Updated : 2024-08-07 21:29
NVD link : CVE-2024-23460
Mitre link : CVE-2024-23460
CVE.ORG link : CVE-2024-23460
JSON object : View
Products Affected
zscaler
- client_connector
CWE
CWE-347
Improper Verification of Cryptographic Signature