LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-1709: ConnectWise ScreenConnect Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 22, 2024
CVSS 10.0 · Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
10.0
CVSS score
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 29, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-1709 to its Known Exploited Vulnerabilities catalog on Feb 22, 2024, with a federal patch deadline of Feb 29, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

CVE-2024-1709 is an authentication bypass vulnerability in ConnectWise ScreenConnect. An attacker who can reach the management interface over the network can create a new administrator-level account on affected systems. This matters because the product is commonly used for remote support and management; successful abuse can give an attacker full administrative control of the ScreenConnect instance and the systems it manages. The vulnerability has been used by ransomware operators, so rapid identification and remediation are essential.

Public technical detail beyond the CISA summary is limited; always confirm exact affected builds, fixed versions, and any additional guidance against the official ConnectWise advisory.

How it works

The flaw is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In essence, the authentication checks that should prevent unauthenticated users from performing privileged actions can be circumvented. With network access to the management interface, an attacker can create a new administrator account without valid credentials. Once that account exists, the attacker can log in with full administrative rights, install additional software, pivot to managed endpoints, or deploy ransomware. Exact request paths or parameters are not provided here; treat any unauthenticated interaction that results in new admin accounts as a high-severity indicator and validate behavior against the vendor advisory.

Am I affected? How to find it in your systems

ConnectWise ScreenConnect is typically deployed as an on-premises remote-support and remote-access server, often exposed to the internet or to partner networks so technicians can connect to client machines. Inventory every instance by searching asset databases, configuration-management tools, and network scans for hosts running ScreenConnect services or listening on the ports the product uses for its web management interface.

If you cannot determine the exact version, assume the instance is vulnerable until proven otherwise by the vendor’s guidance.

How to remediate

Patch first. Apply the vendor-supplied update that addresses CVE-2024-1709 as soon as it can be tested and deployed. Follow the exact upgrade steps and any post-update verification steps published by ConnectWise. CISA’s required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Because this vulnerability is known to be exploited by ransomware groups, any unpatched ScreenConnect instance that was reachable from untrusted networks should be treated as potentially compromised. Investigate for unauthorized administrator accounts, unexpected remote sessions, and indicators of ransomware staging or encryption. Rotate credentials for any accounts that could have been accessed through the ScreenConnect server, and review systems that were managed by it for further compromise. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedConnectWise · ScreenConnect
WeaknessCWE-288
CVSS base score10.0 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
PublishedFeb 21, 2024
Added to CISA KEVFeb 22, 2024
Federal patch deadlineFeb 29, 2024
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities