CVE-2024-23459: Multiple Arbitrary Creates/Overwrites by link following
Published May 2, 2024
·Updated
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.
Affected Software
2 affected components
Zscaler Client Connector<3.7
Zscaler Client Connector Macos<3.7
Event History
May 2, 2024
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:23 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23459?
CVE-2024-23459 has a severity rating that depends on the context of use, but it allows system file overwrites, indicating a potentially high impact.
2
How do I fix CVE-2024-23459?
To fix CVE-2024-23459, update Zscaler Client Connector to version 3.7 or later.
3
Which versions of Zscaler Client Connector are affected by CVE-2024-23459?
CVE-2024-23459 affects Zscaler Client Connector versions before 3.7 on Mac.
4
What type of vulnerability is CVE-2024-23459?
CVE-2024-23459 is an Improper Link Resolution Before File Access vulnerability.
5
What impact does CVE-2024-23459 have on system security?
CVE-2024-23459 can lead to a security risk by allowing unauthorized overwriting of system files.