CVE-2024-23464: Zscaler bypass with administrative privileges on Windows
Published Aug 6, 2024
·Updated
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1
Affected Software
1 affected component
Zscaler Client Connector Windows<4.2.1
Event History
Aug 6, 2024
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23464?
CVE-2024-23464 is considered a critical vulnerability due to its potential to disable Zscaler Internet Access.
2
How do I fix CVE-2024-23464?
To fix CVE-2024-23464, upgrade Zscaler Client Connector to version 4.2.1 or later.
3
What systems are affected by CVE-2024-23464?
CVE-2024-23464 affects Zscaler Client Connector on Windows versions prior to 4.2.1.
4
What can exploit CVE-2024-23464?
CVE-2024-23464 can be exploited using PowerShell commands executed with admin rights.
5
Is there a workaround for CVE-2024-23464?
Currently, there are no known workarounds for CVE-2024-23464 other than applying the required updates.