ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers exploiting ConnectWise ScreenConnect flaws, fixes available for all users (CVE-2024-1709, CVE-2024-1708)

criticalVulnerability exploited in the wildimportance 60CVE-2024-1709CVE-2024-1708

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1709
+1 in the same advisory: …1708
Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts

ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure.

Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use.

10.0
group max
100% KEV ransomware PoC ×3
  • ConnectWise ScreenConnect
masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions…
Full article416 words · extracted from helpnetsecurity.com · click to collapse

The two ScreenConnect vulnerabilities ConnectWise has recently urged customers to patch have finally been assigned CVE numbers: CVE-2024-1709 for the authentication bypass, CVE-2024-1708 for the path traversal flaw.

CVE-2024-1709 CVE-2024-1708

ConnectWise has also released a newer version of ScreenConnect (v23.9.10.8817), which contains the fixes for the two flaws and other non-security fixes but – more crucially – customers no longer under maintenance can upgrade to it to protect themselves against exploitation.

Confirmed exploitation, PoC available

ConnectWise shared the existence of the two flaws on Monday (February 19), when it said that they’ve been reported through their vulnerability disclosure channel via the ConnectWise Trust Center, and urged customers that are self-hosted or on-premise to update their servers to version 23.9.8 as soon as possible.

On Tuesday, the company confirmed exploitation attempts from several IP addresses, and Huntress researchers published their technical analysis of both CVE-2024-1709 and CVE-2024-1708 and a demo of their proof-of-concept exploit for CVE-2024-1709.

WatchTowr Labs has published a proof-of-concept exploit for CVE-2024-1709 (to add a new administrative user in ConnectWise ScreenConnect as a first step in a RCE chain).

“The ‘exploit’ is trivial and embarrassingly easy,” Huntress researchers said, and demonstrated how it could lead to remote code execution. They also shared their own indicators of compromise and detection rules for potential malicious activity.

The Shadowserver Foundation says there are around 3800 vulnerable ConnectWise ScreenConnect instances and that they are picking up the initial exploit request in their honeypot sensors. “Check for signs of compromise (new users added) and patch!” they advised.

Update and check for evidence of compromise

As noted before, ALL ConnectWise ScreenConnect customers can now upgrade to a fixed version – v23.9.10.8817 – and should do it immediately.

“We assess with high confidence that this vulnerability will be actively targeted by various types of threat actors, including cybercriminals and nation-state actors, given the severity and scope of the vulnerability and the nature of the impacted product,” Palo Alto Networks’ Unit 42 opined.

ConnectWise has also provided advice for customers who suspect that they have been compromised via CVE-2024-1709: they should upgrade their ScreenConnect installation and, after logging in, they should check for malicious commands/tools or connections by using the Report Manager extension.

UPDATE (February 23, 2024, 02:00 a.m. ET):

Sophos’ X-Ops task force says they’ve been seeing the ScreenConnect vulnerabilities being actively exploited in the wild to deliver the LockBit ransomware (despite the recent law enforcement operation to disrupt the RaaS operator), AsyncRAT, infostealers, and the SimpleHelp Remote Access Client.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/02/22/cve-2024-1709-cve-2024-1708/