PT-2024-13026 · Zscaler · Win Zapp+3

Published

2024-03-26

·

Updated

2024-06-07

·

CVE-2023-41973

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zscaler Client Connector versions prior to 4.3.0.121
Description The issue arises from ZSATray passing the previousInstallerName as a config parameter to TrayManager. TrayManager then constructs the path and appends previousInstallerName to get the full path of the exe. This can lead to a local privilege escalation.
Recommendations For versions prior to 4.3.0.121, update to Win ZApp 4.3.0.121 or later to resolve the issue. As a temporary workaround, consider restricting access to the TrayManager to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-41973

Affected Products

Traymanager
Win Zapp
Zsatray
Zscaler Client Connector