ZeroHour

CVE-2019-16514

PoC ×2
CVSS 3.1
7.2 high
EPSS
4%p90
Published
()
Modified
Description

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.

Vendors
connectwise
Products
control
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.