CVE-2020-11632: High severity zscaler client connector vulnerability
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11632?
CVE-2020-11632 is a vulnerability in the Zscaler Client Connector prior to version 2.1.2.150 that allows a local adversary to execute code with system privileges.
What is the severity of CVE-2020-11632?
The severity of CVE-2020-11632 is high with a CVSS score of 7.8.
How does CVE-2020-11632 affect Zscaler Client Connector?
CVE-2020-11632 affects Zscaler Client Connector versions prior to 2.1.2.150.
How can I fix CVE-2020-11632?
To fix CVE-2020-11632, users should update to Zscaler Client Connector version 2.1.2.150 or later.
Where can I find more information about CVE-2020-11632?
You can find more information about CVE-2020-11632 on the Zscaler website at [help.zscaler.com](https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2020?applicable_category=Windows&applicable_version=2.1.2.105).