CVE-2024-23463: Anti-Tampering bypass via Repair App functionality
Published Apr 30, 2024
·Updated
Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1
Affected Software
2 affected components
Zscaler Client Connector<4.2.1
Zscaler Client Connector Windows<4.2.1
Event History
Apr 30, 2024
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23463?
CVE-2024-23463 is classified as a medium severity vulnerability due to its potential ability to bypass anti-tampering protections.
2
How do I fix CVE-2024-23463?
To fix CVE-2024-23463, upgrade the Zscaler Client Connector to version 4.2.1 or later.
3
What specifically does CVE-2024-23463 affect?
CVE-2024-23463 affects the anti-tampering protection of the Zscaler Client Connector on Windows prior to version 4.2.1.
4
What conditions lead to CVE-2024-23463 being exploited?
CVE-2024-23463 can be exploited under certain conditions when utilizing the Repair App functionality.
5
Who is impacted by CVE-2024-23463?
Users running Zscaler Client Connector on Windows prior to version 4.2.1 are impacted by CVE-2024-23463.