Lucene search

K
nvd[email protected]NVD:CVE-2023-41971
HistoryMay 02, 2024 - 1:23 p.m.

CVE-2023-41971

2024-05-0213:23:06
CWE-59
web.nvd.nist.gov
zscaler
client connector
windows
vulnerability
file overwrite

CVSS3

5.3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H

EPSS

0

Percentile

9.0%

An Improper Link Resolution Before File Access (β€˜Link Following’) vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.

CVSS3

5.3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-41971