ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Flaws Found in ConnectWise ScreenConnect Software

criticalRansomware exploited in the wildimportance 60CVE-2024-1708CVE-2024-1709

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1709
+1 in the same advisory: …1708
Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts

ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure.

Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use.

10.0
group max
100% KEV ransomware PoC ×3
  • ConnectWise ScreenConnect
masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions…
Full article710 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 20, 2024Vulnerability / Network Security

ConnectWise has released software updates to address two security flaws in its ScreenConnect remote desktop and access software, including a critical bug that could enable remote code execution on affected systems.

The vulnerabilities are listed below -

  • CVE-2024-1708 (CVSS score: 8.4) - Improper limitation of a pathname to a restricted directory aka "path traversal"
  • CVE-2024-1709 (CVSS score: 10.0) - Authentication bypass using an alternate path or channel

The company deemed the severity of the issues as critical, citing they "could allow the ability to execute remote code or directly impact confidential data or critical systems."

Both the vulnerabilities impact ScreenConnect versions 23.9.7 and prior, with fixes available in version 23.9.8. The flaws were reported to the company on February 13, 2024.

While there is no evidence that the shortcomings have been exploited in the wild, users who are running self-hosted or on-premise versions are recommended to update to the latest version as soon as possible.

"ConnectWise will also provide updated versions of releases 22.4 through 23.9.7 for the critical issue, but strongly recommend that partners update to ScreenConnect version 23.9.8," the IT management software company said.

Cybersecurity firm Huntress said it found more than 8,800 servers running a vulnerable version of ScreenConnect. It has also demonstrated a proof-of-concept (PoC) exploit that it said can be “recreated with ease and required minimal technical knowledge” and used to bypass authentication on unpatched ScreenConnect servers.

ConnectWise Flaws Come Under Active Exploitation

ConnectWise has since revised its advisory to note that it has "received updates of compromised accounts," indicating active exploitation of the flaws. It said the attacks originated from the following IP addresses -

  • 155.133.5[.]15
  • 155.133.5[.]14
  • 118.69.65[.]60

The exact scale of the campaign is currently unknown, although cybersecurity company Rapid7 said observed exploitation within customer environments.

Huntress has also shared additional technical details of the two vulnerabilities, stating the exploit is "trivial and embarrassingly easy" and that they are being leveraged to deploy the Cobalt Strike adversary simulation framework for post exploitation.

The shortcomings, in particular, could be weaponized to create a rogue administrator account and take control of ScreenConnect and even access or modify files in other directories, leading to arbitrary code execution.

PoC exploits for the authentication bypass bug have also been released by watchTowr Labs and Horizon3.ai, with the latter describing the flaw as residing in the SetupWizard component that's responsible for creating an initial user and password.

"This vulnerability allows an attacker to create their own administrative user on the ScreenConnect server, giving them full control over the server," James Horseman said. "This vulnerability follows a theme of other recent vulnerabilities that allow attackers to reinitialize applications or create initial users after setup."

ConnectWise ScreenConnect Flaws Exploited to Deliver Ransomware

On February 23, 2024, Huntress and Sophos disclosed that the maximum severity authentication bypass vulnerability has been abused to deliver ransomware payloads generated by the leaked LockBit builder, one of which goes by the name "buhtiRansom."

The British cybersecurity company said it also "saw a different attacker attempt to drop another payload using the certutil utility to download it from a web address, write it to the root of the C:\ drive with the filename svchost.exe, and execute it." While the attack was ultimately unsuccessful, a subsequent analysis has revealed it to be another ransomware variant built on the LockBit builder code.

There are also signs that the flaw has come under widespread exploitation, with numerous opportunistically abusing them to deliver RATs, stealer malware, and cryptocurrency miners such as AsyncRAT, RedLine Stealer, Vidar Stealer, and Redcap.

"One threat actor abused ScreenConnect to push another remote access client to the target machine," Sophos said. "The attacker used ScreenConnect.WindowsClient.exe to launch the SimpleHelp installer. Five hours later, on the same machine, we observed ransom notes appear on the system and files renamed with a different file extension."

The development has also led to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding CVE-2024-1709 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to secure their instances within one week by February 29, 2024.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/02/critical-flaws-found-in-connectwise.html