First published: Mon Oct 23 2023(Updated: )
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
Credit: cve@zscaler.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zscaler Client Connector for Windows | <3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26735 is a vulnerability that affects the Zscaler Client Connector Installer and Uninstallers for Windows.
CVE-2021-26735 has a severity rating of 7.8 out of 10, which is considered high.
CVE-2021-26735 is an unquoted search path vulnerability that allows a local adversary to execute code with SYSTEM privileges.
The Zscaler Client Connector Installer and Uninstallers for Windows prior to version 3.6 are affected by CVE-2021-26735.
Yes, updating Zscaler Client Connector to version 3.6 or above will fix the vulnerability.