Detection Guidance for ConnectWise CWE-288
ID: c8f0f761-c4cb-5de6-9ec1-7a2493b659a4
STIX ID: report--c8f0f761-c4cb-5de6-9ec1-7a2493b659a4
Feed Name: Huntress Blog
Threat Score
Huntress published an analysis of two critical ConnectWise ScreenConnect authentication-bypass vulnerabilities (CVE-2024-1709 & CVE-2024-1708), demonstrating an easily-reproducible proof-of-concept that can create accounts and bypass authentication; the report urges immediate patching to 23.9.8 and provides detection/forensic guidance (modified User.xml, recoverable temp GUID files, IIS log indicators, and Windows Event ID 4663/SACL monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
