CVE-2020-11633: Zscaler Client Connector

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.

Affected products

  • Zscaler Client Connector: before 2.1.2.81 (fixed in 2.1.2.81)

Published 2021-07-15. Last modified 2026-06-17.