CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

zscaler

client_connector

40 known vulnerabilities · sorted by CVSS score

CVE-2020-11633
CRITICAL9.8

The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.

zscaler / client_connector
Network
Published Jul 15, 2021
Page 1 of 2
CVE-2024-23463
HIGH8.8

Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1

zscaler / client_connector
Network
Published Apr 30, 2024
CVE-2023-28799
HIGH8.2

A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.

zscaler / client_connector+5
Network
Published Jun 22, 2023
CVE-2023-28804
HIGH8.2

An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105

zscaler / client_connector
Network
Published Oct 23, 2023
CVE-2023-28800
HIGH8.1

When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.

zscaler / client_connector+5
Network
Published Jun 22, 2023
CVE-2020-11635
HIGH7.8

The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.

zscaler / client_connector
Local
Published Feb 16, 2021
CVE-2024-23457
HIGH7.8

The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209

zscaler / client_connector
Local
Published May 1, 2024
CVE-2024-23456
HIGH7.8

Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

zscaler / client_connector
Local
Published Aug 6, 2024
CVE-2020-11634
HIGH7.8

The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.

zscaler / client_connector
Local
Published Jul 15, 2021
CVE-2020-11632
HIGH7.8

The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.

zscaler / client_connector
Local
Published Jul 15, 2021
CVE-2023-28793
HIGH7.8

Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

zscaler / client_connector
Local
Published Oct 23, 2023
CVE-2021-26738
HIGH7.8

Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.

zscaler / client_connector
Local
Published Oct 23, 2023
CVE-2023-28795
HIGH7.8

Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

zscaler / client_connector
Local
Published Oct 23, 2023
CVE-2024-3661
HIGH7.6

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

fortinet / forticlient+25
Adjacent
Published May 6, 2024
CVE-2024-23480
HIGH7.5

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.

zscaler / client_connector
Local
Published May 1, 2024
CVE-2024-23458
HIGH7.3

While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.

zscaler / client_connector
Local
Published Aug 6, 2024
CVE-2023-41969
HIGH7.3

An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.

zscaler / client_connector
Local
Published Mar 26, 2024
CVE-2023-41973
HIGH7.3

ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.

zscaler / client_connector
Local
Published Mar 26, 2024
CVE-2023-41972
HIGH7.3

In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.

zscaler / client_connector
Local
Published Mar 26, 2024
CVE-2024-23464
HIGH7.2

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

zscaler / client_connector
Network
Published Aug 6, 2024