Vulnerability Reproduced: Immediately Patch ScreenConnect 23.9.8
ID: 5f502c90-6822-5b66-840d-236d1ccb24f6
STIX ID: report--5f502c90-6822-5b66-840d-236d1ccb24f6
Feed Name: Huntress Blog
**Huntress discovered and validated proof-of-concept exploits for two critical ConnectWise ScreenConnect vulnerabilities (CVE-2024-1709 & CVE-2024-1708) — an authentication bypass (CWE-288, base score 10) and a path traversal (CWE-22, base score 8.4).** They deployed a temporary hotfix to 1,000+ managed systems, reported ~8,800 vulnerable servers visible on Censys, advised on-premises users to immediately update to ScreenConnect 23.9.8, and noted no confirmed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
