CVE-2024-23458 Information

Description

While copying individual autoupdater log files reparse point check was missing which could result into crafted attacks potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.

Reference

https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=windows&applicable_version=4.2.0.190

Share on: