CVE-2026-59565

8.8

Zscaler · Client Connector

A buffer overflow vulnerability in Zscaler Client Connector for Windows allows an authenticated attacker to trigger a local and kernel denial of service.

Executive summary

A high severity buffer overflow vulnerability in Zscaler Client Connector for Windows allows authenticated attackers to cause a kernel level denial of service.

Vulnerability

The flaw is a buffer overflow, identified as CWE-229, occurring within the Zscaler Client Connector on Windows. It requires low privileges for exploitation and results in a denial of service that impacts both the local application and the kernel.

Business impact

The ability to trigger a kernel level denial of service can lead to system instability, unexpected reboots, and significant operational downtime for affected Windows endpoints. Given the CVSS score of 8.8, this represents a major risk to business continuity, particularly for remote workforces relying on Zscaler for secure connectivity.

Remediation

Immediate Action: Update Zscaler Client Connector to the latest versions specified in the vendor release summary to ensure the buffer overflow flaw is resolved.

Proactive Monitoring: Monitor endpoint health and system event logs for repeated service crashes or system bug checks related to the Zscaler service.

Compensating Controls: Restrict local user permissions on endpoints to prevent non-administrative users from interacting with sensitive services that may be susceptible to this overflow.

Exploitation status

Public Exploit Available: false

Analyst recommendation

All organizations deploying Zscaler Client Connector on Windows must prioritize upgrading to the patched versions. Ensuring that endpoints are running the latest software is critical to maintaining network security and preventing service outages caused by this vulnerability.

More Zscaler CVEs