logo

SlashAndGrab: The ConnectWise ScreenConnect Vulnerability Explained | Huntress

ID: 77a5d963-0774-52ec-b144-648e6eee761d

STIX ID: report--77a5d963-0774-52ec-b144-648e6eee761d

Feed Name: Huntress Blog

Threat Score
88/100

Date Published: 2024-02-26

Date Updated: 2026-04-28

...
...

Huntress documents a critical authentication-bypass and path-traversal vulnerability in ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708) exploitable via a trivial "SlashAndGrab" technique; public PoCs enabled rapid in-the-wild abuse where attackers deployed ransomware, coin miners, and backdoors. Huntress conducted rapid analysis, issued detections and Sigma rules, deployed a protective vaccine to endpoints, and published post-exploitation tradecraft and remediation guidance to help defenders hunt and remediate compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.