PT-2024-1800 · Connectwise · Connectwise Screenconnect

Published

2024-02-21

·

Updated

2026-05-12

·

CVE-2024-1708

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ConnectWise ScreenConnect versions prior to 23.9.8
Description A path traversal flaw exists due to improper restriction of directory path names. This allows a remote attacker to bypass directory restrictions, potentially enabling the upload of malicious extensions to achieve remote code execution. Such exploitation can directly impact critical systems and confidential data. There are confirmed real-world incidents of active exploitation, where attackers have used this issue for privilege escalation and lateral movement across connected systems.
Recommendations Update to a version newer than 23.9.7. Review logs and rotate credentials to mitigate risks from potential prior compromise.

Exploit

Fix

RCE

LPE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01532
CVE-2024-1708

Affected Products

Connectwise Screenconnect