First published: Thu Jul 15 2021(Updated: )
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
Credit: cve@zscaler.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zscaler Client Connector for Windows | <2.1.2.150 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11632 is a vulnerability in the Zscaler Client Connector prior to version 2.1.2.150 that allows a local adversary to execute code with system privileges.
The severity of CVE-2020-11632 is high with a CVSS score of 7.8.
CVE-2020-11632 affects Zscaler Client Connector versions prior to 2.1.2.150.
To fix CVE-2020-11632, users should update to Zscaler Client Connector version 2.1.2.150 or later.
You can find more information about CVE-2020-11632 on the Zscaler website at [help.zscaler.com](https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2020?applicable_category=Windows&applicable_version=2.1.2.105).