CVE-2024-23460

MEDIUM

Zscaler Client Connector < 4.2 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

Scores

CVSS v3 6.4
EPSS 0.0003
EPSS Percentile 7.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
zscaler/client_connector < 4.2
Published Aug 06, 2024
Tracked Since Feb 18, 2026