First published: Tue Feb 16 2021(Updated: )
The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.
Credit: cve@zscaler.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zscaler Client Connector for Windows | <3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11635.
The title of this vulnerability is 'The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients.'
The severity of CVE-2020-11635 is high, with a severity value of 7.8.
The Zscaler Client Connector versions prior to 3.1.0 are affected by this vulnerability.
An attacker can exploit this vulnerability to execute code with system privileges or perform limited actions for which they did not have privileges.