PT-2024-19878 · Zscaler · Zscaler Client Connector

Published

2024-08-06

·

Updated

2024-11-11

·

CVE-2024-23456

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zscaler Client Connector versions prior to 4.2.0.190
Description The issue allows anti-tampering to be disabled under certain conditions without signature validation. It is being actively exploited in the wild, and users should check their network for signs of compromise.
Recommendations For versions prior to 4.2.0.190, update to version 4.2.0.190 or later to resolve the issue. As a temporary workaround, consider restricting access to features that rely on anti-tampering until a patch is applied.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2024-23456

Affected Products

Zscaler Client Connector