logo

A Catastrophe For Control: Understanding the ScreenConnect Authentication Bypass | Huntress Blog

ID: ed8f1dd8-bdc6-5781-985d-72ffef7bd6be

STIX ID: report--ed8f1dd8-bdc6-5781-985d-72ffef7bd6be

Feed Name: Huntress Blog

Threat Score
88/100

Date Published: 2024-02-21

Date Updated: 2026-04-28

...
...

Huntress analyzed ConnectWise ScreenConnect vulnerabilities (CVE-2024-1709 and CVE-2024-1708) and recreated a trivial authentication-bypass exploit they call “SlashAndGrab” that can allow an attacker to create admin credentials and achieve remote code execution via ScreenConnect extensions or a ZipSlip-style path traversal; the report includes technical details of the flaw, proof-of-concept behavior, and detection guidance and IOCs for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.