CVE-2024-1708

9.5 CISA KEV

ConnectWise · ScreenConnect

A path traversal vulnerability in ConnectWise ScreenConnect (23.9.7 and prior) allows unauthenticated attackers to execute remote code or access confidential data.

Executive summary

This critical path traversal vulnerability in ConnectWise ScreenConnect is actively exploited in the wild and poses a severe risk of unauthorized system access and remote code execution.

Vulnerability

This is a path traversal flaw (CWE-22) that allows an unauthenticated attacker to bypass authentication mechanisms. The vulnerability permits the execution of remote code or unauthorized access to sensitive system data.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected ScreenConnect server, potentially leading to total system compromise, data exfiltration, or the deployment of ransomware across managed endpoints. Given the CVSS score of 9.5, this is a critical security event that requires immediate attention to prevent catastrophic operational disruption. The vulnerability is considered a catastrophe for control, as it directly impacts the integrity of remote management infrastructure.

Remediation

Immediate Action: Update all instances of ConnectWise ScreenConnect to version 23.9.8 or later immediately to remediate the vulnerability.

Proactive Monitoring: Review system and application logs for unusual file access patterns, unexpected process execution originating from the ScreenConnect service, and unauthorized authentication attempts.

Compensating Controls: If immediate patching is not feasible, isolate the ScreenConnect server from public network access or deploy Web Application Firewall (WAF) rules designed to detect and block path traversal attempts.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and various public proof-of-concept repositories are available.

Analyst recommendation

The severity of this vulnerability, combined with confirmed active exploitation, makes immediate patching mandatory. Organizations should prioritize updating their ScreenConnect infrastructure to version 23.9.8 and conduct a thorough security audit of the environment to identify any signs of prior unauthorized access.

More ConnectWise CVEs

Sources