ZeroHour
The Recordpublished ()ingested

ConnectWise remote access software needs immediate patching, company says

criticalData breach exploited in the wildimportance 60CVE-2024-1709

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1709
Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts

ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure.

Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use.

10.0100% KEV ransomware PoC ×3
  • ConnectWise ScreenConnect
masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions…
Full article249 words · extracted from therecord.media · click to collapse

IT management software company ConnectWise is urging users to update self-hosted versions of its ScreenConnect product “immediately” because of critical bugs that can allow easy intrusions by outsiders.

In its latest update to a security bulletin on the issue, the company says it has “received updates of compromised accounts that our incident response team have been able to investigate and confirm.” One of the vulnerabilities was disclosed with a CVSS score of 10, the highest possible.

ScreenConnect allows for secure remote desktop access and mobile device support. ConnectWise says the cloud-based versions of the software have been patched, but any organization running an on-premises or a self-hosted version should “immediately” update it.

Exploiting the bugs “is trivial and embarrassingly easy” according to a blog post by cybersecurity company Huntress. Attackers can remotely execute code on a compromised network.

Cybersecurity company watchTowr also posted a proof of concept on the GitHub repository that shows how exploitation could occur.

ConnectWise initially published an advisory, thin on details, on Monday. Huntress said that once it had recreated the exploit and attack chain, it was “too dangerous for this information to be readily available to threat actors,” but the company decided to “spill the beans” on Wednesday once other vendors published information.

The researchers summarized how an attack might occur in a 34-second video.


_Editor's Note: The Cybersecurity and Infrastructure Security Agency (CISA) added the ConnectWise bug to its list of Known Exploited Vulnerabilities on Thursday, February 22, with the number [CVE-2024-1709](https://nvd.nist.gov/vuln/detail/CVE-2024-1709)._

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/connectwise-software-needs-immediate-patching