Executive brief
Zscaler Client Connector (ZCC) is a security agent installed on endpoints to route traffic through Zscaler's cloud security platform. A race condition flaw in its ZPA tunnel handler can corrupt memory, causing the client to crash (denial of service) or potentially allowing attackers to execute arbitrary code with the privileges of the ZCC process.
Technical details
A race condition exists in the ZPA tunnel handler component of affected Zscaler Client Connector versions, leading to heap corruption. The vulnerability can be triggered by an attacker with network access to the ZPA tunnel protocol; no authentication is required. Successful exploitation results in client-side denial of service (application crash) and may enable arbitrary code execution in the context of the ZCC process, potentially compromising the endpoint's security posture.
Affected products
- Zscaler Client Connector <UNKNOWN>
Timeline
- 2026-09-14: disclosed