CVE-2024-23482: ZScalerService Local Privilege Escalation
Published Mar 26, 2024
·Updated
The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.
Affected Software
2 affected components
Zscaler ZApp<4.2.0.241
Zscaler Client Connector Macos<4.2.0.241
Event History
Mar 26, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23482?
CVE-2024-23482 is categorized as a local privilege escalation vulnerability.
2
How do I fix CVE-2024-23482?
To fix CVE-2024-23482, upgrade to Mac ZApp version 4.2.0.241 or later.
3
What software is affected by CVE-2024-23482?
CVE-2024-23482 affects users running ZScaler ZApp versions prior to 4.2.0.241.
4
What is the impact of CVE-2024-23482?
The impact of CVE-2024-23482 allows local users to escalate their privileges by exploiting the ZScalerService process.
5
Is there a workaround for CVE-2024-23482?
Currently, the recommended solution is to update the ZScaler ZApp to the fixed version.