The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
2024-08-06T16:15:47.460
2024-08-07T21:29:01.067
Analyzed
CVSSv3.1: 6.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zscaler | client_connector | < 4.2 | Yes |