CVE-2023-41973: Lack of input santization on Zscaler Client Connector enables arbitrary code execution
Published Mar 26, 2024
·Updated
ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.
Affected Software
3 affected components
Zscaler Zscaler Client Connector<4.3.0.121
Zscaler Win ZApp>=4.3.0.121
Zscaler Client Connector Windows<4.3.0.121
Event History
Mar 26, 2024
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41973?
CVE-2023-41973 has been classified as a significant vulnerability due to improper access controls.
2
How do I fix CVE-2023-41973?
To fix CVE-2023-41973, upgrade to Win ZApp version 4.3.0.121 or later.
3
Which versions of Zscaler Client Connector are affected by CVE-2023-41973?
CVE-2023-41973 affects Zscaler Client Connector versions prior to 4.3.0.121.
4
What software products are impacted by CVE-2023-41973?
The impacted products include Zscaler Client Connector and Win ZApp versions below 4.3.0.121.
5
When was CVE-2023-41973 disclosed?
CVE-2023-41973 was disclosed in September 2023.