Executive brief
Zscaler Client Connector is a security software that protects endpoints by enforcing security policies and controlling network traffic. Unprivileged users on affected systems can escalate their privileges and execute arbitrary code with system-level access, potentially compromising the entire device and bypassing security controls.
Technical details
Multiple vulnerabilities in Zscaler Client Connector allow local privilege escalation (LPE) attacks. The vulnerabilities enable unprivileged local users to execute arbitrary code in a privileged context, typically through a flaw in how the application handles permissions or processes. Attack preconditions require local access to the affected system. An attacker with a standard user account can gain administrative or system privileges, leading to full device compromise. Fixes are expected in patched versions; users should check Zscaler's release notes for the specific affected versions and available patches.
Affected products
- Zscaler Client Connector
Timeline
- 2026-08-24: disclosed