CVE Tools
Back to feed
Advisory ScreenConnect Remote Access web-app ConnectWise

ConnectWise warns of new ScreenConnect flaw without patch

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

ConnectWise has published an emergency security advisory for a new vulnerability in ScreenConnect Remote Access that impacts file transfer behavior in Support and Access sessions. Because the company has not yet released a permanent fix, administrators are instructed to manually revoke the TransferFiles (or TransferFilesInSession) permission from user roles as a temporary mitigation. While no CVE ID has been assigned to this specific issue, Shadowserver data indicates nearly 6,000 ScreenConnect instances remain exposed to the internet, increasing the risk of exploitation given the product's history of targeting by ransomware groups and state-sponsored actors.