CVE-2024-1709

Confirmed PUBLISHED

Authentication bypass using an alternate path or channel

ConnectWise · ScreenConnect
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 100.0%

At a Glance

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

metasploit ransomware nuclei_scanner cisa malware
CVE Published
Feb 21, 2024
Exploitation Reported
Feb 22, 2024
CVSS
10.0 Critical
EPSS
100.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
connectwise
screenconnect

0 to <= 23.9.7

Affected
ConnectWise
ScreenConnect

0 to <= 23.9.7

Changed to unaffected at 23.9.8

Affected

CVE References

Show 5 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.