PT-2024-1800 · Connectwise · Connectwise Screenconnect
Published
2024-02-21
·
Updated
2026-05-12
·
CVE-2024-1708
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ConnectWise ScreenConnect versions prior to 23.9.8
Description
A path traversal flaw exists due to improper restriction of directory path names. This allows a remote attacker to bypass directory restrictions, potentially enabling the upload of malicious extensions to achieve remote code execution. Such exploitation can directly impact critical systems and confidential data. There are confirmed real-world incidents of active exploitation, where attackers have used this issue for privilege escalation and lateral movement across connected systems.
Recommendations
Update to a version newer than 23.9.7.
Review logs and rotate credentials to mitigate risks from potential prior compromise.
Exploit
Fix
RCE
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Screenconnect