Junglewise Threat Intelligence

CVE-2024-1708: ConnectWise ScreenConnect path traversal

CVE-2024-1708 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2026-04-28

Executive brief

ConnectWise ScreenConnect, a remote desktop and support software, contains a security flaw that allows unauthorized access to restricted files. An attacker could exploit this to take control of the server, potentially leading to the theft of sensitive customer data or a total service outage. This vulnerability has been actively used in ransomware attacks to compromise corporate networks.

Technical details

A path traversal vulnerability (CWE-22) exists in ConnectWise ScreenConnect versions 23.9.7 and prior. The flaw allows an attacker with high privileges to bypass directory restrictions, potentially leading to remote code execution (RCE) or unauthorized access to sensitive system files. While the CVSS vector indicates high privileges and user interaction are required, the vulnerability has been observed in the wild being used in conjunction with other flaws to facilitate ransomware operations. A fix is available in version 23.9.8.

Affected products

  • ConnectWise ScreenConnect 23.9.7 and prior

CVE identifiers

  • CVE-2024-1708
  • CVE-2026-32202

Timeline

  • 2024-02-21: disclosed
  • 2024-02-21: advisory: Vendor security bulletin released
  • 2024-02-21: patched: Fixed in version 23.9.8
  • 2026-04-28: kev added: Added to CISA KEV catalog due to active exploitation

Related threats