Executive brief
Zscaler Client Connector is a security application used to protect corporate devices by inspecting internet traffic for threats. A configuration issue during the application's startup on Windows may allow a small amount of network traffic to bypass security inspections under specific, rare conditions. This could potentially allow unverified data to enter or leave the device before the security software is fully active.
Technical details
A vulnerability in the startup configuration of Zscaler Client Connector for Windows (versions 4.7.x before 4.7.0.141 and 4.8.x before 4.8.0.63) can lead to a race condition or improper initialization sequence. This flaw, classified under CWE-1289 (Improper Validation of Unsafe Equivalence in Input), results in a failure to intercept and inspect a limited volume of network traffic during the initial boot or application start phase. While the attack vector is listed as network-based, exploitation typically requires specific timing or user interaction (UI:R) to trigger the uninspected traffic flow. Zscaler has addressed this in updated versions of the Client Connector.
Affected products
- Zscaler Client Connector 4.7 before 4.7.0.141, 4.8 before 4.8.0.63
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory