VendorsZscalerclient_connectorall versions
Vulnerabilities

Zscaler Client Connector

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

41CVEs
CVE-2020-11633
The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.
Published 2021-07-15 · Modified
10.0EPSS 0.019
CVE-2024-23483
Local Privilege Escalation via lack of input validation
Published 2024-08-06 · Analyzed
9.8EPSS 0.007
CVE-2024-23459
Multiple Arbitrary Creates/Overwrites by link following
Published 2024-05-02 · Analyzed
9.8EPSS 0.005
CVE-2023-28798
Out-of-bounds write to heap in pacparser
Published 2024-05-02 · Analyzed
9.8EPSS 0.004
CVE-2023-28805
ZCC on Linux privilege escalation
Published 2023-10-23 · Modified
9.8EPSS 0.003
CVE-2024-23480
Insecure MacOS code sign check fallback
Published 2024-05-01 · Analyzed
9.8EPSS 0.003
CVE-2024-23463
Anti-Tampering bypass via Repair App functionality
Published 2024-04-30 · Analyzed
8.8EPSS 0.004
CVE-2023-28799
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
Published 2023-06-22 · Modified
8.2EPSS 0.004
CVE-2023-28804
Linux ZCC allows unsigned updates, allowing elevated Code Execution
Published 2023-10-23 · Modified
8.2EPSS 0.002
CVE-2023-28800
Output encoding missing in redrurl parameter
Published 2023-06-22 · Modified
8.1EPSS 0.005
CVE-2020-11634
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.
Published 2021-07-15 · Modified
7.8EPSS 0.005
CVE-2020-11635
The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.
Published 2021-02-16 · Modified
7.8EPSS 0.004
CVE-2020-11632
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
Published 2021-07-15 · Modified
7.8EPSS 0.003
CVE-2023-41973
Lack of input santization on Zscaler Client Connector enables arbitrary code execution
Published 2024-03-26 · Analyzed
7.8EPSS 0.003
CVE-2023-28793
Heap Based Buffer Overflow in Library
Published 2023-10-23 · Modified
7.8EPSS 0.003
CVE-2024-23482
ZScalerService Local Privilege Escalation
Published 2024-03-26 · Analyzed
7.8EPSS 0.003
CVE-2023-41972
Revert password check incorrect type validation
Published 2024-03-26 · Analyzed
7.8EPSS 0.002
CVE-2021-26738
Privilege Escalation for ZCC macOS via PATH Variable
Published 2023-10-23 · Modified
7.8EPSS 0.002
CVE-2024-23456
Signature validation issue leads to Anti-Tampering bypass
Published 2024-08-06 · Analyzed
7.8EPSS 0.002
CVE-2021-26736
ZApp Installer Privilege Escalation Vulnerabilities
Published 2023-10-23 · Modified
7.8EPSS 0.002
CVE-2024-23457
Anti-tampering can be disabled with uninstall password enforced
Published 2024-05-01 · Analyzed
7.8EPSS 0.002
CVE-2023-41971
Windows ZCC Upgrade DoS And Privilege Escalation Through RPC Control
Published 2024-05-02 · Analyzed
7.8EPSS 0.002
CVE-2023-28796
IPC Bypass Through PLT Section in ELF
Published 2023-10-23 · Modified
7.8EPSS 0.002
CVE-2023-28795
Client IPC validation bypass
Published 2023-10-23 · Modified
7.8EPSS 0.001
CVE-2021-26735
Untrusted Search Path While Executing REG DELETE by Uninstaller
Published 2023-10-23 · Modified
7.8EPSS 0.001
CVE-2024-23460
Incorrect signature validation of package
Published 2024-08-06 · Analyzed
7.8EPSS 0.001
CVE-2024-23458
Local Privilege Escalation on Zscaler Client Connector on Windows
Published 2024-08-06 · Analyzed
7.8EPSS 0.001
CVE-2023-41970
Repair App local code execution with arbitrary privileges
Published 2024-05-02 · Analyzed
7.8EPSS 0.001
CVE-2024-3661
DHCP routing options can manipulate interface-based VPN traffic
Published 2024-05-06 · Analyzed
7.6EPSS 0.041
CVE-2024-23462
ZCC Mac validinstaller file integrity check missing
Published 2024-05-02 · Analyzed
7.5EPSS 0.002
CVE-2023-41969
ZSATrayManager Arbitrary File Deletion
Published 2024-03-26 · Analyzed
7.3EPSS 0.003
CVE-2023-28797
LPE using arbitrary file delete with Symlinks
Published 2023-10-23 · Modified
7.3EPSS 0.002
CVE-2024-23464
Zscaler bypass with administrative privileges on Windows
Published 2024-08-06 · Analyzed
7.2EPSS 0.004
CVE-2023-28803
Traffic being bypassed by ZCC by configuring synthetic IP range as local network
Published 2023-10-23 · Modified
6.5EPSS 0.003
CVE-2023-28794
PAC Files Exposed to Internet Websites
Published 2023-11-06 · Modified
6.5EPSS 0.002
CVE-2023-28806
Signature validation error in DLL allows disabling anti-tampering protection
Published 2024-08-06 · Analyzed
6.5EPSS 0.002
CVE-2021-26734
Junction Delete leading to elevation of privilege
Published 2023-10-23 · Modified
5.5EPSS 0.001
CVE-2024-23461
ZCC macOS Upgrade ZIP Bomb DoS
Published 2024-05-02 · Analyzed
5.5EPSS 0.001
CVE-2021-26737
Privilege Escalation Using PID Reuse in ZCC macOS
Published 2023-10-23 · Modified
5.5EPSS 0.001
CVE-2023-28802
Disable Zscaler using machine tunnel restart
Published 2023-11-21 · Modified
5.4EPSS 0.002
1 / 2Next →