The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.
References
Link | Resource |
---|---|
https://trust.zscaler.com/posts/7316 | Vendor Advisory |
Configurations
Information
Published : 2021-02-16 12:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-11635
Mitre link : CVE-2020-11635
JSON object : View
CWE
Products Affected
zscaler
- client_connector