CVE-2024-31127: MacOS Zscaler Client Connector Local Privilege Escalation
Published Jun 4, 2025
·Updated
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
Affected Software
1 affected component
Zscaler Client Connector<4.2.0.241
Event History
Jun 4, 2025
CVE Published
via MITRE·04:45 AM
Data Sourced
via MITRE·04:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31127?
CVE-2024-31127 has a high severity level as it allows local attackers to elevate their privileges.
2
How do I fix CVE-2024-31127?
To fix CVE-2024-31127, upgrade your Zscaler Client Connector to version 4.2.0.241 or higher.
3
Who is affected by CVE-2024-31127?
CVE-2024-31127 affects users of Zscaler Client Connector on Mac versions prior to 4.2.0.241.
4
What type of vulnerability is CVE-2024-31127?
CVE-2024-31127 is classified as a privilege escalation vulnerability due to improper verification of loaded libraries.
5
What impact does CVE-2024-31127 have on systems?
CVE-2024-31127 can potentially allow unauthorized users to gain elevated privileges on affected systems.