PT-2020-9830 · Connectwise · Connectwise Control
Matt Hamilton
·
Published
2020-01-23
·
Updated
2020-01-28
·
CVE-2019-16514
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ConnectWise Control versions 19.3.25270.7185
Description
An issue in ConnectWise Control allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.
Recommendations
For version 19.3.25270.7185, consider restricting access to the extension upload feature to prevent potential exploitation until a fix is available. As a temporary workaround, limit administrative user privileges to minimize the risk of uploading malicious ZIP files.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Control