CVE-2020-11633: Buffer Overflow
The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11633?
CVE-2020-11633 is a vulnerability in the Zscaler Client Connector for Windows, allowing an attacker to execute arbitrary code with system privileges.
How severe is CVE-2020-11633?
CVE-2020-11633 has a severity score of 9.8 out of 10, indicating a critical vulnerability.
How does CVE-2020-11633 work?
CVE-2020-11633 exploits a stack-based buffer overflow in the Zscaler Client Connector for Windows when connecting to misconfigured TLS servers.
Which versions of Zscaler Client Connector for Windows are affected by CVE-2020-11633?
Zscaler Client Connector for Windows versions up to (excluding) 2.1.2.81 are affected by CVE-2020-11633.
How can I fix CVE-2020-11633?
To fix CVE-2020-11633, it is recommended to update Zscaler Client Connector for Windows to version 2.1.2.81 or higher.