ZeroHour
The Recordpublished ()ingested

ConnectWise says nation-state attack targeted multiple ScreenConnect customers

highThreat actorimportance 60CVE-2024-1709

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1709
Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts

ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure.

Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use.

10.0100% KEV ransomware PoC ×3
  • ConnectWise ScreenConnect
masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions…
Full article449 words · extracted from therecord.media · click to collapse

IT management software company ConnectWise said it is investigating a nation-state attack on its systems that impacted some of its customers. 

The company declined to provide details about the incident but told Recorded Future News that it “recently learned of suspicious activity” within its environment that it believes “was tied to a sophisticated nation state actor, which affected a very small number of ScreenConnect customers.”

ScreenConnect is the company’s flagship IT remote management and monitoring software and is used by dozens of governments and large businesses. Hackers have frequently targeted vulnerabilities in the software, using it as a jumping off point for ransomware attacks and data thefts. 

ConnectWise said it has launched an investigation with forensic experts from Mandiant. 

“We have communicated with all affected customers and are coordinating with law enforcement. As part of our work with Mandiant, we patched ScreenConnect and implemented enhanced monitoring and hardening measures across our environment,” a spokesperson said. 

“We have not observed any further suspicious activity in any customer instances.”

The company did not respond to a request for additional details. The incident was first reported by CRN. 

ScreenConnect allows for secure remote desktop access and mobile device support. It is a popular enterprise tool that is widely used by managed service providers (MSPs), which are attractive to cybercriminals and nation states because they can serve as staging points to launch attacks on other businesses. 

Both China and Russia have been seen exploiting ConnectWise ScreenConnect vulnerabilities in the last two years. 

Researchers from Google said in February that a hacker affiliated with China’s Ministry of State Security exploited CVE-2024-1709 in ConnectWise ScreenConnect “to compromise hundreds of institutions primarily in the U.S. and Canada.”

The same bug was used repeatedly by Chinese state-backed hackers to attack U.S. defense contractors, U.K. government entities and institutions in Asia throughout 2024, according to Mandiant. Other security experts called the bug a “catastrophe” due to how trivial it was to exploit. 

Sandworm, which researchers have tied to Russian Military Intelligence Unit 74455, was also seen using it in attacks, according to Microsoft. 

The Cybersecurity and Infrastructure Security Agency (CISA), which did not respond to requests for comment about the ConnectWise incident, previously warned that cybercriminals used versions of ScreenConnect themselves during attacks on at least two federal civilian agencies. 

The Florida-based ConnectWise was purchased by private equity giant Thoma Bravo in 2019.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/connectwise-nation-state-attack-targeted-some-customers