ZeroHour

CVE-2024-23460

CVSS 3.1
7.8 high
EPSS
<1%p3
Published
()
Modified
Description

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

Vendors
zscaler
Products
client connector
Weakness
CWE-347
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.