CVE-2024-1708
Improper limitation of a pathname to a restricted directory (“path traversal”)
Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
In plain language
AI Act nowCVE-2024-1708 is a path-traversal weakness in ConnectWise ScreenConnect that can let a malicious insider (a highly privileged user) reach files outside allowed folders; if you run ScreenConnect, you should treat this as urgent and update.
CVE-2024-1708 is a path traversal (CWE-22) in ConnectWise ScreenConnect that allows a high-privilege attacker to access files outside the intended restricted directory, enabling unauthorized code execution and/or sensitive data access; CISA lists it as exploited in ransomware activity (KEV).
What to do now
- Check your ConnectWise ScreenConnect version and confirm whether you are running 23.9.7 or earlier.
- If you’re affected, upgrade ConnectWise ScreenConnect to 23.9.8 (or later if available).
- After upgrading, review authentication/administrative activity and logs for unusual file access or configuration changes around the time of any suspected activity.
- If you cannot upgrade immediately, follow ConnectWise vendor mitigation steps referenced for the fixed release and restrict access paths to reduce exposure while the update is pending.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-1708 and every CVE in our database. Create a free account — no credit card required.
Create Free Account