First published: Thu May 02 2024(Updated: )
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.
Credit: cve@zscaler.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zscaler | <3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41971 is classified as a high severity vulnerability due to the potential impact of system file overwriting.
To fix CVE-2023-41971, upgrade Zscaler Client Connector to version 3.7 or later.
The impact of CVE-2023-41971 is that it allows malicious actors to overwrite critical system files on Windows machines.
CVE-2023-41971 affects Zscaler Client Connector on Windows versions prior to 3.7.
There are no official workarounds for CVE-2023-41971; upgrading to the patched version is the recommended approach.