CVE-2024-23460

MEDIUM

Zscaler Client Connector < 4.2 - Unauthenticated Arbitrary Code Execution via Unsigned Installer

Title source: llm
STIX 2.1

Description

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

Scores

CVSS v3 6.4
EPSS 0.0013
EPSS Percentile 2.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
zscaler/client_connector < 4.2
Published Aug 06, 2024
Tracked Since Feb 18, 2026