ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Ransomware Warning as CVSS 10.0 ScreenConnect Bug is Exploited

criticalRansomware exploited in the wildimportance 60CVE-2024-1709CVE-2024-1708

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1709
+1 in the same advisory: …1708
Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts

ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure.

Do: Follow ConnectWise's instructions immediately: no patch existed at disclosure, so apply the vendor's mitigations or, per the CISA KEV required action, restrict internet exposure of the management interface or discontinue use until mitigations are available, then upgrade to the vendor's patched release as soon as it ships. Audit ScreenConnect servers for unexpectedly created administrator-level accounts and unusual remote sessions, which are the attack's artifacts. Prioritize any instance whose management interface is reachable from the internet, given confirmed in-the-wild exploitation and known ransomware use.

10.0
group max
100% KEV ransomware PoC ×3
  • ConnectWise ScreenConnect
masstens of thousands of internet-exposed ScreenConnect servers (on the order of 10,000-30,000 instances in public internet scans at disclosure), managing millions…
Full article288 words · extracted from infosecurity-magazine.com · click to collapse

IT admins have been urged to patch any on-premises ScreenConnect servers immediately, after reports that a recently published maximum severity vulnerability is being exploited in the wild.

CVE-2024-1709 is an authentication bypass bug which has been given a CVSS score of 10.0. It can be exploited without user interaction to execute arbitrary code and access sensitive data in low-complexity attacks.

ConnectWise, the maker of the remote desktop software application, also revealed a path traversal vulnerability with a CVSS score of 8.4 – subsequently labelled CVE-2024-1708.

Cloud customers have already had their instances updated, but on-premises customers must take action.

Read more on ScreenConnect: CISA Warns Against Malicious Use of Legitimate RMM Software

“Partners that are self-hosted or on-premises need to update their servers to version 23.9.8 immediately to apply a patch,” the vendor said. “We’ve received notifications of suspicious activity that our incident response team has investigated.”

Separately, Huntress CEO, Kyle Hanslovan, cited a US intelligence source as saying that initial access brokers currently exploiting the CVSS 10.0 bug will inevitably sell to ransomware actors.

“The sheer prevalence of this software and the access afforded by this vulnerability signals we are on the cusp of a ransomware free-for-all. Hospitals, critical infrastructure, and state institutions are proven at risk,” he warned.

“With remote access software, the bad guys can push ransomware as easily as the good guys can push a patch. And once they start pushing their data encryptors, I’d be willing to bet 90% of preventative security software won’t catch it because it’s coming from a trusted source.”

The Shadowserver Foundation claimed in a tweet yesterday that around 3800 ConnectWise ScreenConnect instances are still vulnerable to exploitation of both bugs.

— Shadowserver (@Shadowserver) February 21, 2024

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomware-cvss-100-screenconnect/