CVE-2026-22569
- EPSS 0.08%
- Veröffentlicht 31.03.2026 14:54:57
- Zuletzt bearbeitet 06.04.2026 15:15:09
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
CVE-2025-54983
- EPSS 0.01%
- Veröffentlicht 12.11.2025 03:07:39
- Zuletzt bearbeitet 15.04.2026 00:35:42
A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.
CVE-2024-31127
- EPSS 0.03%
- Veröffentlicht 04.06.2025 04:45:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
CVE-2024-23483
- EPSS 0.39%
- Veröffentlicht 06.08.2024 16:15:47
- Zuletzt bearbeitet 07.08.2024 21:23:09
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.
CVE-2024-23464
- EPSS 0.07%
- Veröffentlicht 06.08.2024 16:15:47
- Zuletzt bearbeitet 07.08.2024 21:23:59
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1
CVE-2024-23460
- EPSS 0.03%
- Veröffentlicht 06.08.2024 16:15:47
- Zuletzt bearbeitet 07.08.2024 21:29:01
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
CVE-2024-23458
- EPSS 0.04%
- Veröffentlicht 06.08.2024 16:15:47
- Zuletzt bearbeitet 07.08.2024 21:29:09
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.
CVE-2024-23456
- EPSS 0.06%
- Veröffentlicht 06.08.2024 16:15:47
- Zuletzt bearbeitet 07.08.2024 21:30:09
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.
CVE-2023-28806
- EPSS 0.02%
- Veröffentlicht 06.08.2024 16:15:46
- Zuletzt bearbeitet 07.08.2024 21:29:17
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.
CVE-2024-3661
- EPSS 2.91%
- Veröffentlicht 06.05.2024 19:15:11
- Zuletzt bearbeitet 15.01.2025 16:50:28
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local...