PT-2025-52259 · Connectwise · Screenconnect

·

CVE-2025-14823

·

Published

2025-12-18

·

Updated

2025-12-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ScreenConnect versions prior to 1.0.12
Description In deployments utilizing the Certificate Signing Extension, encrypted configuration values, potentially including an Azure Key Vault-related key, could be disclosed to unauthenticated users via a client-facing endpoint under specific circumstances. While the values were encrypted and securely stored, their encrypted representation was potentially exposed in client responses. The issue relates to configuration handling occurring on the client side, allowing encrypted values to be transmitted to and rendered by client components.
Recommendations Update the Certificate Signing Extension to version 1.0.12 or higher to ensure configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14823

Affected Products

Screenconnect