Vulnerability Description
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zscaler | Client Connector | < 4.1 |
Related Weaknesses (CWE)
References
- https://help.zscaler.com/client-connector/client-connector-app-release-summary-2Release Notes
- https://help.zscaler.com/client-connector/client-connector-app-release-summary-2Release Notes
FAQ
What is CVE-2023-28797?
CVE-2023-28797 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user. ...
How severe is CVE-2023-28797?
CVE-2023-28797 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28797?
Check the references section above for vendor advisories and patch information. Affected products include: Zscaler Client Connector.