logo

Critical Flaws Found in ConnectWise ScreenConnect Software - Patch Now

ID: a376a9dc-7480-51a6-aa8a-a1071e86a727

STIX ID: report--a376a9dc-7480-51a6-aa8a-a1071e86a727

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Executive Summary: ConnectWise released fixes for two critical ScreenConnect flaws (CVE-2024-1709 authentication bypass, CVE-2024-1708 path traversal) that affect versions up to 23.9.7; proof-of-concept exploits and active exploitation have been observed—threat actors have used the bugs to create administrative accounts, deploy Cobalt Strike and LockBit-derived ransomware (including "buhtiRansom"), and deliver RATs, stealers, and miners; CISA has added CVE-2024-1709 to its KEV catalog and vendors/incident responders report widespread opportunistic abuse and IoCs including specific attacker IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.