Zscaler Client Connector Zero-interaction Privilege Escalation Vulnerability
ID: b705c10b-006c-5691-91ee-ac696d2409c3
STIX ID: report--b705c10b-006c-5691-91ee-ac696d2409c3
Feed Name: cybersecurityNews.com
The report describes a local privilege escalation in Zscaler Client Connector where three vulnerabilities (CVE-2023-41972, CVE-2023-41973, CVE-2023-41969) can be chained to escalate a standard user to NT AUTHORITY\\SYSTEM by bypassing RPC caller validation, abusing an incorrect password-type check in the PERFORM_APP_REVERT function, leveraging path-traversal in previousInstallerName to execute an attacker-controlled installer, and performing DLL hijacking; Zscaler has released fixes in versions 4.2.0.209 / 4.3.0.121 and later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
