First published: Thu Jul 15 2021(Updated: )
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.
Credit: cve@zscaler.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zscaler Client Connector for Windows | <2.1.2.105 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-11634 is high with a severity value of 7.8.
The DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634) is caused due to the configuration of OpenSSL.
The DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634) allows a local adversary to execute arbitrary code in the SYSTEM context.
Zscaler Client Connector for Windows prior to version 2.1.2.105 is affected by CVE-2020-11634.
To fix the DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634), update to version 2.1.2.105 or later.