CVE-2024-23457

HIGH

Zscaler Client Connector <4.2.0.209 - Info Disclosure

Title source: llm
STIX 2.1

Description

The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
zscaler/client_connector < 4.2.0.209
Published May 01, 2024
Tracked Since Feb 18, 2026