PT-2025-52259 · Connectwise · Screenconnect
Michael Gilliam
·
Published
2025-12-18
·
Updated
2025-12-19
·
CVE-2025-14823
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ScreenConnect versions prior to 1.0.12
Description
In deployments utilizing the Certificate Signing Extension, encrypted configuration values, potentially including an Azure Key Vault-related key, could be disclosed to unauthenticated users via a client-facing endpoint under specific circumstances. While the values were encrypted and securely stored, their encrypted representation was potentially exposed in client responses. The issue relates to configuration handling occurring on the client side, allowing encrypted values to be transmitted to and rendered by client components.
Recommendations
Update the Certificate Signing Extension to version 1.0.12 or higher to ensure configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Screenconnect