CVE-2023-41971

An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:windows:*:*

History

02 Mar 2026, 19:14

Type Values Removed Values Added
References () https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2021??applicable_category=windows&applicable_version=3.7 - () https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2021??applicable_category=windows&applicable_version=3.7 - Vendor Advisory, Release Notes
CPE cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:windows:*:*
First Time Zscaler client Connector
Zscaler

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2021??applicable_category=windows&applicable_version=3.7 - () https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2021??applicable_category=windows&applicable_version=3.7 -
Summary
  • (es) Una vulnerabilidad de resolución de enlace incorrecta antes del acceso al archivo ("siguiente enlace") en Zscaler Client Connector en Windows permite sobrescribir un archivo del sistema. Este problema afecta a Client Connector en Windows: versiones anteriores a 3.7.

02 May 2024, 13:23

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 13:23

Updated : 2026-03-02 19:14


NVD link : CVE-2023-41971

Mitre link : CVE-2023-41971

CVE.ORG link : CVE-2023-41971


JSON object : View

Products Affected

zscaler

  • client_connector
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')