CVE-2023-28797: LPE using arbitrary file delete with Symlinks
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
CVE-2023-28797
What is the title of this vulnerability?
LPE using arbitrary file delete with Symlinks
What is the description of this vulnerability?
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.
What software is affected by this vulnerability?
Zscaler Client Connector for Windows before version 4.1.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is high, with a CVSS score of 7.3.
How can I fix this vulnerability?
To fix this vulnerability, ensure you have updated to Zscaler Client Connector for Windows version 4.1 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the Zscaler Client Connector release summary for 2022 at: https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022
What Common Weakness Enumeration (CWE) ID is associated with this vulnerability?
This vulnerability is associated with CWE-59.