The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.
References
Link | Resource |
---|---|
https://trust.zscaler.com/posts/7316 | Vendor Advisory |
https://trust.zscaler.com/posts/7316 | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://trust.zscaler.com/posts/7316 - Vendor Advisory |
Information
Published : 2021-02-16 20:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11635
Mitre link : CVE-2020-11635
CVE.ORG link : CVE-2020-11635
JSON object : View
Products Affected
zscaler
- client_connector
CWE