CVE-2020-11635: High severity zscaler client connector vulnerability
Published Feb 16, 2021
·Updated
The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.
Affected Software
1 affected component
Zscaler Client Connector Windows<3.1.0
Event History
Feb 16, 2021
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security flaw?
The vulnerability ID is CVE-2020-11635.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients.'
3
What is the severity of CVE-2020-11635?
The severity of CVE-2020-11635 is high, with a severity value of 7.8.
4
Which software versions are affected by this vulnerability?
The Zscaler Client Connector versions prior to 3.1.0 are affected by this vulnerability.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to execute code with system privileges or perform limited actions for which they did not have privileges.