CVE-2025-54983

MEDIUM

Zscaler Client Connector <4.6.0.216-<4.7.0.47 - Use After Free

Title source: llm
STIX 2.1

Description

A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.

Scores

CVSS v3 5.2
EPSS 0.0002
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-772
Status published
Products (2)
Zscaler/Zscaler Client Connector 4.6 - 4.6.0.216
Zscaler/Zscaler Client Connector 4.7 - 4.7.0.47
Published Nov 12, 2025
Tracked Since Feb 18, 2026