← Volver a CVEs
CVE-2024-23457
HIGH7.8
Descripcion
The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209
Detalles CVE
Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado5/1/2024
Ultima modificacion3/2/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
zscaler:client_connector
Debilidades (CWE)
CWE-269
Referencias
https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023(cve@zscaler.com)
https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.