CVE-2026-59565
8.8Zscaler · Client Connector
A buffer overflow vulnerability in Zscaler Client Connector for Windows allows an authenticated attacker to trigger a local and kernel denial of service.
Executive summary
A high severity buffer overflow vulnerability in Zscaler Client Connector for Windows allows authenticated attackers to cause a kernel level denial of service.
Vulnerability
The flaw is a buffer overflow, identified as CWE-229, occurring within the Zscaler Client Connector on Windows. It requires low privileges for exploitation and results in a denial of service that impacts both the local application and the kernel.
Business impact
The ability to trigger a kernel level denial of service can lead to system instability, unexpected reboots, and significant operational downtime for affected Windows endpoints. Given the CVSS score of 8.8, this represents a major risk to business continuity, particularly for remote workforces relying on Zscaler for secure connectivity.
Remediation
Immediate Action: Update Zscaler Client Connector to the latest versions specified in the vendor release summary to ensure the buffer overflow flaw is resolved.
Proactive Monitoring: Monitor endpoint health and system event logs for repeated service crashes or system bug checks related to the Zscaler service.
Compensating Controls: Restrict local user permissions on endpoints to prevent non-administrative users from interacting with sensitive services that may be susceptible to this overflow.
Exploitation status
Public Exploit Available: false
Analyst recommendation
All organizations deploying Zscaler Client Connector on Windows must prioritize upgrading to the patched versions. Ensuring that endpoints are running the latest software is critical to maintaining network security and preventing service outages caused by this vulnerability.