CVE-2021-26735: Untrusted Search Path While Executing REG DELETE by Uninstaller
Published Oct 23, 2023
·Updated
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
Affected Software
1 affected component
Zscaler Client Connector Windows<3.6
Event History
Oct 23, 2023
CVE Published
01:19 PM
Data Sourced
01:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-26735?
CVE-2021-26735 is a vulnerability that affects the Zscaler Client Connector Installer and Uninstallers for Windows.
2
What is the severity of CVE-2021-26735?
CVE-2021-26735 has a severity rating of 7.8 out of 10, which is considered high.
3
How does CVE-2021-26735 work?
CVE-2021-26735 is an unquoted search path vulnerability that allows a local adversary to execute code with SYSTEM privileges.
4
Which software versions are affected by CVE-2021-26735?
The Zscaler Client Connector Installer and Uninstallers for Windows prior to version 3.6 are affected by CVE-2021-26735.
5
Is there a fix for CVE-2021-26735?
Yes, updating Zscaler Client Connector to version 3.6 or above will fix the vulnerability.