CVE-2024-23480

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*

History

17 Feb 2026, 19:15

Type Values Removed Values Added
References () https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=macos&applicable_version=4.2 - () https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=macos&applicable_version=4.2 - Vendor Advisory, Release Notes
First Time Zscaler client Connector
Zscaler
CPE cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:macos:*:*

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=macos&applicable_version=4.2 - () https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=macos&applicable_version=4.2 -
Summary
  • (es) Un mecanismo alternativo en la verificación de signos de código en macOS puede permitir la ejecución de código arbitrario. Este problema afecta a Zscaler Client Connector en MacOS anteriores a 4.2.

01 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 17:15

Updated : 2026-02-17 19:15


NVD link : CVE-2024-23480

Mitre link : CVE-2024-23480

CVE.ORG link : CVE-2024-23480


JSON object : View

Products Affected

zscaler

  • client_connector
CWE
CWE-347

Improper Verification of Cryptographic Signature