ScreenConnect Vulnerabilities
ID: a71d2393-f07e-59be-b2f0-e93505133874
STIX ID: report--a71d2393-f07e-59be-b2f0-e93505133874
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive Summary:** This report documents exploitation of ScreenConnect vulnerabilities (CVE-2024-1709 and CVE-2024-1708) where a malformed HTTP request to SetupWizard.aspx enables unauthenticated creation of an administrator account and upload of a malicious ASHX extension to achieve remote code execution, followed by deployment of ToddlerShark malware with links to the Kimsuky APT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
