The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.


CVSS 3.x Severity and Metrics:

CVSS 2.0 Severity and Metrics:

References to Advisories, Solutions, and Tools

Weakness Enumeration

CWE-346 Origin Validation Error NIST   Zscaler, Inc.  

Change History

Initial Analysis by NIST 10/26/2023 8:33:45 PM

Added CPE Configuration
     *cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:* versions up to (excluding) 3.6
Added CVSS V3.1
Added CWE
Changed Reference Type No Types Assigned Release Notes

Zscaler, Inc.