Description
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-13524 | The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition. |
References
History
No history.
Status: PUBLISHED
Assigner: Zscaler
Published:
Updated: 2024-09-11T14:32:14.147Z
Reserved: 2021-02-05T20:34:27.824Z
Link: CVE-2021-26737
Updated: 2024-08-03T20:33:40.693Z
Status : Modified
Published: 2023-10-23T14:15:09.127
Modified: 2024-11-21T05:56:46.830
Link: CVE-2021-26737
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD