CVE-2020-11634: High severity zscaler client connector vulnerability
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11634?
The severity of CVE-2020-11634 is high with a severity value of 7.8.
How does the DLL hijacking vulnerability occur in Zscaler Client Connector for Windows (CVE-2020-11634)?
The DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634) is caused due to the configuration of OpenSSL.
What is the impact of the DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634)?
The DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634) allows a local adversary to execute arbitrary code in the SYSTEM context.
Which version of Zscaler Client Connector for Windows is affected by CVE-2020-11634?
Zscaler Client Connector for Windows prior to version 2.1.2.105 is affected by CVE-2020-11634.
How can I fix the DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634)?
To fix the DLL hijacking vulnerability in Zscaler Client Connector for Windows (CVE-2020-11634), update to version 2.1.2.105 or later.