logo

Detection Guidance for ConnectWise CWE-288

ID: c8f0f761-c4cb-5de6-9ec1-7a2493b659a4

STIX ID: report--c8f0f761-c4cb-5de6-9ec1-7a2493b659a4

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-02-21

Date Updated: 2026-04-28

...
...

Huntress published an analysis of two critical ConnectWise ScreenConnect authentication-bypass vulnerabilities (CVE-2024-1709 & CVE-2024-1708), demonstrating an easily-reproducible proof-of-concept that can create accounts and bypass authentication; the report urges immediate patching to 23.9.8 and provides detection/forensic guidance (modified User.xml, recoverable temp GUID files, IIS log indicators, and Windows Event ID 4663/SACL monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.