CVE-2021-26738: Privilege Escalation for ZCC macOS via PATH Variable
Published Oct 23, 2023
·Updated
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.
Affected Software
1 affected component
Zscaler Client Connector Macos<3.7
Event History
Oct 23, 2023
CVE Published
01:24 PM
Data Sourced
01:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-26738?
CVE-2021-26738 is a vulnerability known as Privilege Escalation for ZCC macOS via PATH Variable.
2
What is the severity of CVE-2021-26738?
The severity of CVE-2021-26738 is high. It has a severity value of 7.8.
3
How does CVE-2021-26738 affect Zscaler Client Connector?
CVE-2021-26738 affects Zscaler Client Connector for macOS versions up to and excluding 3.7.
4
How can a local adversary exploit CVE-2021-26738?
A local adversary can exploit CVE-2021-26738 by manipulating the PATH variable and executing code with root privileges.
5
How can I fix the CVE-2021-26738 vulnerability in Zscaler Client Connector?
To fix the CVE-2021-26738 vulnerability, update Zscaler Client Connector for macOS to version 3.7 or a later version.