CVE-2020-11633

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
15/07/2021
Last modified:
27/07/2021

Description

The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zscaler:client_connector:*:*:*:*:*:windows:*:* 2.1.2.81 (excluding)