PT-2024-1800 · Connectwise · Connectwise Screenconnect

CVE-2024-1708

·

Published

2024-02-21

·

Updated

2026-09-12

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ConnectWise ScreenConnect versions prior to 23.9.8
Description A path traversal flaw exists due to improper restriction of directory path names. This allows a remote attacker to bypass directory restrictions, potentially enabling the upload of malicious extensions to achieve remote code execution. Such exploitation can directly impact critical systems and confidential data. Real-world incidents have confirmed active exploitation, where attackers used the flaw to perform privilege escalation and lateral movement across connected client networks.
Recommendations Update ConnectWise ScreenConnect to version 23.9.8 or later. Review system logs for signs of compromise. Rotate all credentials. Implement runtime segmentation to limit the potential impact of a compromised management infrastructure.

Exploit

Fix

LPE

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01532
CVE-2024-1708

Affected Products

Connectwise Screenconnect