Search Results (42 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-23460 1 Zscaler 1 Client Connector 2024-08-06 6.4 Medium
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
CVE-2024-23458 1 Zscaler 1 Client Connector 2024-08-06 7.3 High
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.