PT-2024-13026 · Zscaler · Win Zapp+3
Published
2024-03-26
·
Updated
2024-06-07
·
CVE-2023-41973
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zscaler Client Connector versions prior to 4.3.0.121
Description
The issue arises from ZSATray passing the
previousInstallerName as a config parameter to TrayManager. TrayManager then constructs the path and appends previousInstallerName to get the full path of the exe. This can lead to a local privilege escalation.Recommendations
For versions prior to 4.3.0.121, update to Win ZApp 4.3.0.121 or later to resolve the issue. As a temporary workaround, consider restricting access to the TrayManager to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traymanager
Win Zapp
Zsatray
Zscaler Client Connector