CVE-2021-26736: ZApp Installer Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26736?
CVE-2021-26736 is a vulnerability in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 that allows execution of binaries from a low privileged path, potentially enabling a local adversary to execute code with SYSTEM privileges.
How does CVE-2021-26736 affect Zscaler Client Connector?
CVE-2021-26736 affects Zscaler Client Connector versions prior to 3.6 on Windows.
What is the severity of CVE-2021-26736?
The severity of CVE-2021-26736 is high, with a CVSS score of 7.8.
How can an attacker exploit CVE-2021-26736?
An attacker with local access to the system can exploit CVE-2021-26736 by executing binaries from a low privileged path, potentially gaining SYSTEM privileges.
Is there a fix for CVE-2021-26736?
Yes, upgrading to Zscaler Client Connector version 3.6 or later addresses CVE-2021-26736.