Critical ConnectWise ScreenConnect vulnerabilities fixed, patch ASAP!
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-1709 +1 in the same advisory: …1708 | Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure. Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use. | 10.0 group max | 100% | KEV ransomware PoC ×3 |
| masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions… |
Full article489 words · extracted from helpnetsecurity.com · click to collapse
UPDATE (February 22, 2024, 05:40 a.m. ET):
Now designated as CVE-2024-1709 and CVE-2024-1708, the vulnerabilities are under active exploitation. Go here for up-to-date information and advice.

ConnectWise has fixed two vulnerabilities in ScreenConnect that could allow attackers to execute remote code or directly impact confidential data or critical systems.
“There is no evidence that these vulnerabilities have been exploited in the wild, but immediate action must be taken by on-premise partners to address these identified security risks,” the company said.
About ConnectWise ScreenConnect
ConnectWise ScreenConnect (formerly ConnectWise Control, before the latest change to the original name) is a remote desktop software solution popular with managed services providers and businesses they offer services to, as well as help desk teams.
The product is offered as cloud-hosted software-as-a-service or can be deployed by organizations as a self-hosted server application (either in the cloud or on-premises). When users require remote assistance, they are instructed to join a session by visiting an URL and downloading client software.
ConnectWise ScreenConnect is also popular tech support scammers and other cyber criminals, including ransomware gangs.
In late 2022, ConnectWise disabled the customization feature for trial accounts for the cloud-hosted service, to prevent scammers from creating branded support portals and trick employees into joining a malicious remote access session.
About the vulnerabilities
The two vulnerabilities – currently without a CVE number – affect ScreenConnect 23.9.7 and prior and are categorized as:
- Authentication bypass using an alternate path or channel
- Improper limitation of a pathname to a restricted directory (“path traversal”)
They were reported on February 13, 2024 through the company’s vulnerability disclosure channel.
Even though there is currently no evidence that these vulnerabilities have been exploited, ConnectWise says they are at a higher risk of being targeted by exploits.
“Partners that are self-hosted or on-premise need to update their servers to version 23.9.8 immediately to apply a patch,” the company said.
“ConnectWise will also provide updated versions of releases 22.4 through 23.9.7 for the critical issue, but strongly recommend that partners update to ScreenConnect version 23.9.8.”
UPDATE (February 21, 2024, 04:32 a.m. ET):
ConnectWise has updated the advisory with indicators of compromise (IP addresses) linked to attacks leveraging the auth bypass vulnerability.
“We received updates of compromised accounts that our incident response team have been able to investigate and confirm,” the company says.
“These indicators can be incorporated into your cybersecurity monitoring platform. They can help you stop a cyberattack that’s in progress. Plus, you can use IOCs to find ways to detect and stop ransomware, malware, and other cyberthreats before they cause data breaches.”
WatchTowr Labs has published a proof-of-concept exploit the vulnerability to add a new administrative user in ConnectWise ScreenConnect (as a first step in a trivial RCE chain).
Huntress researchers have created a proof-of-concept exploit (but haven’t published it yet), and have “identified a way to temporarily hot-fix vulnerable systems while administrators work to patch their systems.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/02/20/connectwise-screenconnect-vulnerabilities/