CVE-2024-23460: Incorrect signature validation of package
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23460?
CVE-2024-23460 is considered a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-23460?
To fix CVE-2024-23460, update Zscaler Client Connector to version 4.2 or higher as it addresses the digital signature validation issue.
Who is affected by CVE-2024-23460?
CVE-2024-23460 affects users of Zscaler Client Connector on MacOS versions prior to 4.2.
What types of attacks could exploit CVE-2024-23460?
CVE-2024-23460 could be exploited to execute arbitrary code on affected systems, potentially leading to unauthorized access or data breaches.
Is there a workaround for CVE-2024-23460?
Currently, there are no known workarounds for CVE-2024-23460, and the recommended action is to update the software.