ConnectWise ScreenConnect vulnerability report
ID: 226a2d55-00ed-57bc-873a-a4c67287d1e8
STIX ID: report--226a2d55-00ed-57bc-873a-a4c67287d1e8
Feed Name: ThreatLocker Blog
Threat Score
ConnectWise ScreenConnect versions 23.9.7 and earlier contain two critical security flaws—an authentication bypass (CVSS 10.0) and a path traversal vulnerability (CVSS 8.4)—that can enable remote code execution or unauthorized disclosure of files; ConnectWise released fixes in ScreenConnect 23.9.8 and advises immediate patching for on-premise deployments, though no exploitation in the wild has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
