CVE-2024-23480

HIGH

Zscaler Client Connector <4.2 - RCE

Title source: llm
STIX 2.1

Description

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 21.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
zscaler/client_connector < 4.2
Published May 01, 2024
Tracked Since Feb 18, 2026