ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-1708CVE-2026-32202

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1708
Path Traversal RCE in ConnectWise ScreenConnect (CVE-2024-1708)

ConnectWise ScreenConnect 23.9.7 and prior contain a path-traversal flaw (CWE-22, rated 8.4 high) that can allow an attacker to execute remote code or access confidential data and critical systems. Public analysis (Huntress) shows it is triggered by manipulating directory paths in the product's administrative setup wizard, and that it is typically chained with a companion authentication-bypass flaw (CVE-2024-1709) disclosed at the same time to achieve unauthenticated remote code execution on the ScreenConnect server. An attacker who compromises a ScreenConnect server gains control of the remote-access platform itself and can pivot to every endpoint that server manages, making it an efficient foothold for ransomware. Any organization running ScreenConnect 23.9.7 or earlier is affected, most commonly MSPs and IT teams that use the tool to manage client and internal machines. The flaw is being actively exploited in the wild: it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, EPSS puts the 30-day exploitation probability at 95.5% (100th percentile), and recent reporting ties fast-moving exploitation to the Storm-1175 activity cluster, which drops Medusa ransomware.

Do: Immediately update all self-hosted ScreenConnect instances to a release newer than 23.9.7 per ConnectWise's advisory, and ensure the companion authentication-bypass flaw (CVE-2024-1709) is patched at the same time; federal agencies must follow BOD 22-01 mitigation timelines per the KEV listing. Because exploitation is fast-moving and linked to ransomware operations, hunt for signs of compromise such as unexpected new administrative accounts, setup-wizard activity, or unusual remote sessions on exposed servers. Separately, ConnectWise has disclosed a breach of its own infrastructure by a nation-state actor, so review vendor communications for any updated guidance.

8.495% KEV ransomware PoC
  • ConnectWise ScreenConnect 23.9.7 and prior
large≈ tens of thousands of ScreenConnect deployments (thousands of internet-exposed servers; millions of managed endpoints)
CVE-2026-32202
Spoofing Flaw in Windows Shell (CVE-2026-32202) Actively Exploited

A protection mechanism in the Windows Shell fails (CWE-693), allowing an unauthorized attacker to perform spoofing against the shell over a network. Per the CVSS vector, the attack is network-based, requires no privileges or special conditions, but does require the targeted user to interact with attacker-supplied content. The impact is limited to confidentiality: an attacker can misrepresent information presented through the Windows Shell, gaining a spoofing foothold rather than code execution, privilege escalation, or persistence. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is exposed, which effectively means most Windows estates. Microsoft has confirmed active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-04-28, and a fix shipped in Microsoft's April 2026 Patch Tuesday release.

Do: Apply Microsoft's April 2026 security updates to all affected Windows 10, Windows 11, and Windows Server hosts as a priority; the flaw is on CISA's KEV catalog, so U.S. federal agencies must patch within BOD 22-01 timelines or apply vendor-recommended mitigations. Until patched, note that exploitation requires user interaction with spoofed shell content, so user awareness about verifying shell-rendered information is a partial mitigations. No public PoC is known, but confirmed in-the-wild exploitation warrants prioritizing user-facing and internet-reachable systems for patching.

4.364% KEV
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • microsoft Windows 10 21H2
  • +9 more
mass~1 billion+ Windows devices (affected builds span all supported Windows 10 and Windows 11 desktops plus Windows Server 2012-2022)
Full article267 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2024-1708 (CVSS score of 8.4) ConnectWise ScreenConnect Path Traversal Vulnerability
  • CVE-2026-32202 (CVSS score of 4.3) Microsoft Windows Protection Mechanism Failure Vulnerability

CVE-2024-02-21 is a path traversal vulnerability affecting ConnectWise ScreenConnect versions 23.9.7 and earlier. The issue stems from improper restriction of file paths, allowing attackers to access files and directories outside the intended scope.

By exploiting this flaw, an attacker could manipulate file paths to reach sensitive areas of the system. In certain scenarios, this may lead to remote code execution or unauthorized access to confidential data and critical resources, posing a serious risk to affected environments.

The second flaw added to the catalog is a Windows Shell Spoofing vulnerability tracked as CVE-2026-32202. The flaw allows attackers to spoof content over a network due to a failure in built-in protection mechanisms.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by May 12, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/191442/security/u-s-cisa-adds-microsoft-windows-shell-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html