vulnerability

Zscaler Client Connector: CVE-2024-23458: Origin Validation Error

Severity
6
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:P)
Published
Aug 6, 2024
Added
Jun 5, 2025
Modified
Jun 6, 2025

Description

While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows less than4.2.0.190.

Solution

zscaler-client-connector-update-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.