CVE-2024-1709
Authentication bypass using an alternate path or channel
Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
In plain language
AI Act nowCVE-2024-1709 is an authentication-bypass flaw in ConnectWise ScreenConnect that lets an attacker access sensitive data or control the system without logging in—so any small business using ScreenConnect 23.9.7 or older should treat it as a serious emergency and patch immediately.
CVE-2024-1709 is an authentication bypass in ConnectWise ScreenConnect where attackers can reach protected functionality over the network without authentication (bypassing login restrictions), enabling access to confidential data or system-impacting actions on unpatched versions (fixed in 23.9.8).
What to do now
- Check your ConnectWise ScreenConnect version and confirm whether it is 23.9.7 or earlier.
- Upgrade ScreenConnect to 23.9.8 (or the next vendor-recommended fixed version) immediately.
- If you cannot patch right now, disable or restrict external access to ScreenConnect (allow only trusted internal networks/IPs) until an upgrade is completed.
- After upgrading, verify the service is running the new version and review access logs for any suspicious “no-login” access attempts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- Critical ScreenConnect flaw now actively exploited in attacksen-us·BleepingComputer· Exploited ScreenConnect Kimsuky
- ConnectWise warns of new ScreenConnect flaw without patchen-us·BleepingComputer· Advisory ScreenConnect Remote Access web-app
- Attackers spread malware through ScreenConnect file transfersen-us·Help Net Security· Exploited ScreenConnect malware
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawen·The Hacker News· Exploited StormEncryptor Storm-1175
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-1709 and every CVE in our database. Create a free account — no credit card required.
Create Free Account