CVE-2025-14265

9.1

ConnectWise · ScreenConnect

ConnectWise ScreenConnect prior to version 25.8 fails to validate the integrity of extensions, potentially allowing authorized users to execute arbitrary code or access sensitive configuration data.

Executive summary

A critical vulnerability in ConnectWise ScreenConnect allows authenticated administrative users to execute arbitrary code on the server due to insufficient extension integrity checks.

Vulnerability

This vulnerability, categorized as CWE-494, stems from a lack of server-side validation during the extension installation process. An attacker with administrative privileges can leverage this flaw to install malicious extensions, leading to remote code execution or unauthorized access to sensitive application configuration data.

Business impact

The ability to execute arbitrary code on a ScreenConnect server poses a severe risk, as this software is typically used for remote management and support. With a CVSS score of 9.1, the potential for total system compromise, data theft, and lateral movement within the network is significant. Such an exploit could lead to full loss of control over the managed environment and significant reputational damage.

Remediation

Immediate Action: Cloud-hosted instances are already patched by the vendor. On-premises customers must upgrade their ScreenConnect server and guest clients to version 25.8 immediately.

Proactive Monitoring: Monitor server access logs for suspicious administrative activity, particularly involving the installation or modification of extensions.

Compensating Controls: Ensure that administrative access to the ScreenConnect management console is restricted to trusted personnel and protected by multi-factor authentication to limit the pool of potential attackers.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full server compromise, all on-premises ConnectWise ScreenConnect deployments must be prioritized for patching. Administrators should verify their current version and apply the update to 25.8 without delay to ensure the integrity of the extension subsystem is restored.

More ConnectWise CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Analyst report written
  4. Fix documented version 4.4.0.16 per CVE record

Sources

Originally found and disclosed by Paul Whiting (Ultraviolet Cyber), per the CVE Program record.