CVSS3
Attack Vector
ADJACENT
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
Low
EPSS
Percentile
9.5%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
[
{
"vendor": "Zscaler",
"product": "Client Connector",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.2",
"versionType": "custom"
}
],
"platforms": [
"MacOS"
],
"defaultStatus": "unaffected"
}
]
[
{
"cpes": [
"cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*"
],
"vendor": "zscaler",
"product": "client_connector",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.2",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
CVSS3
Attack Vector
ADJACENT
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
Low
EPSS
Percentile
9.5%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total