CVE-2024-23460
—CVSS 3.1
7.8 high
EPSS
<1%p3
Published
()
Modified
Description
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
- Vendors
- zscaler
- Products
- client connector
- Weakness
- CWE-347
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.