ConnectWise Security Updates – 21 February 2024

ConnectWise has released security updates to fix multiple vulnerabilities across ConnectWise ScreenConnect 23.9.7 and prior.

The addressed vulnerabilities could allow the remote attacker to bypass security restrictions and obtain administrative access, or traverse directories and obtain sensitive information by sending a specially crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on the affected system.

The addressed vulnerabilities:

1. CWE-288: ConnectWise ScreenConnect Security Bypass Vulnerability:

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

2. CWE-22: ConnectWise ScreenConnect Directory Traversal Vulnerability:

  • CVSS: 8.4
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: Required
  • Consequences: Obtain Information
Vulnerabilities
  • CWE-288
  • CWE-22
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

ConnectWise Security Bulletin

References