First published: Mon Oct 23 2023(Updated: )
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.
Credit: cve@zscaler.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zscaler Client Connector for Windows | <3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26736 is a vulnerability in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 that allows execution of binaries from a low privileged path, potentially enabling a local adversary to execute code with SYSTEM privileges.
CVE-2021-26736 affects Zscaler Client Connector versions prior to 3.6 on Windows.
The severity of CVE-2021-26736 is high, with a CVSS score of 7.8.
An attacker with local access to the system can exploit CVE-2021-26736 by executing binaries from a low privileged path, potentially gaining SYSTEM privileges.
Yes, upgrading to Zscaler Client Connector version 3.6 or later addresses CVE-2021-26736.