Executive brief
ConnectWise ScreenConnect versions 23.9.7 and prior are vulnerable to an authentication bypass using an alternate path or channel. This allows a remote, unauthenticated attacker to gain administrative access, potentially leading to the creation of new administrator accounts and full system compromise.
Affected products
- ConnectWise ScreenConnect 23.9.7 and prior
Timeline
- 2024-02-22: disclosed
- 2024-02-22: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2024-02-22: advisory: NVD publication date.