CVE-2023-41971Link Following in Client Connector

CWE-59Link Following3 documents3 sources
Severity
7.8HIGHNVD
CNA5.3
EPSS
0.1%
top 82.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2

Description

An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Windows ZCC Upgrade DoS And Privilege Escalation Through RPC Control2024-05-02
GHSA
GHSA-h695-7mxq-qwxc: An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be over2024-05-02
CVE-2023-41971 — Link Following in Client Connector | cvebase