Zscaler Client Connector是Zscaler公司的一个轻量级代理。 Zscaler Client Connector 4.2.0.190之前版本存在安全漏洞,该漏洞源于缺少重新解析点检查,可能导致精心策划的攻击,从而导致本地特权升级。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zscaler | Client Connector | 0 ~ 4.2.0.190 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-23456 | 7.8 HIGH | Signature validation issue leads to Anti-Tampering bypass |
| CVE-2024-23464 | 7.2 HIGH | Zscaler bypass with administrative privileges on Windows |
| CVE-2024-23483 | 7.0 HIGH | Local Privilege Escalation via lack of input validation |
| CVE-2024-23460 | 6.4 MEDIUM | Incorrect signature validation of package |
| CVE-2023-28806 | 5.7 MEDIUM | Signature validation error in DLL allows disabling anti-tampering protection |
No comments yet