Critical Vulnerabilities in ConnectWise ScreenConnect Patched
ID: 8419bc1e-051f-5a8f-9feb-e08696605818
STIX ID: report--8419bc1e-051f-5a8f-9feb-e08696605818
Feed Name: Arctic Wolf Blog
On February 19, 2024 ConnectWise published a bulletin for on‑premises ScreenConnect addressing two critical vulnerabilities — an authentication-bypass that can lead to remote code execution (CVSS 10) and a path traversal issue (CVSS 8.4). Cloud-hosted ScreenConnect instances have been updated; organizations running on-premises ScreenConnect 23.9.7 or earlier are advised to immediately upgrade to 23.9.8. Arctic Wolf warns threat actors are highly likely to target these severe, low-complexity flaws given ScreenConnect’s historical misuse, though no active exploitation or PoC had been observed at the time of the advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
