PT-2024-1800 · Connectwise · Connectwise Screenconnect
CVE-2024-1708
·
Published
2024-02-21
·
Updated
2026-09-12
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ConnectWise ScreenConnect versions prior to 23.9.8
Description
A path traversal flaw exists due to improper restriction of directory path names. This allows a remote attacker to bypass directory restrictions, potentially enabling the upload of malicious extensions to achieve remote code execution. Such exploitation can directly impact critical systems and confidential data. Real-world incidents have confirmed active exploitation, where attackers used the flaw to perform privilege escalation and lateral movement across connected client networks.
Recommendations
Update ConnectWise ScreenConnect to version 23.9.8 or later.
Review system logs for signs of compromise.
Rotate all credentials.
Implement runtime segmentation to limit the potential impact of a compromised management infrastructure.
Exploit
Fix
LPE
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Screenconnect