The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.
https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=macOS&applicable_version=3.6&deployment_date=2022-01-07&id=1388686
Source: Mitre, NVD
Published: 2023-10-23
Updated: 2023-10-27
Base Score: 3.8
Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C
Severity: Low
Base Score: 4.7
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity: Medium