ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool

Enterprise IT software giant ConnectWise has released urgent patches for two critical security defects in its ScreenConnect remote desktop access product, warning there is high risk of in-the-wild exploitation.
A second bug, documented as an improper limitation of a pathname to a restricted directory was also fixed and tagged with a CVSS severity score of 8.4/10. The company says the vulnerabilities were reported a week ago through its public disclosure channel but insists there is no evidence of in-the-wild exploitation.
Affected versions include ScreenConnect 23.9.7 and prior versions and the company said it is most relevant on on-prem or self-hosted customers.
The ConnectWise ScreenConnect patches come at a time when the US government is warning about critical risks associated with legitimate remote monitoring and management software.
Enterprise IT service providers use RMM applications to remotely manage client networks and endpoints, but threat actors have been caught abusing these tools to hack into companies to launch ransomware attacks.
In malicious campaigns observed in 2022, threat actors sent phishing emails to deploy legitimate RMM software such as ScreenConnect and AnyDesk on victims' systems, and abuse these for financial gain.
Security defects in ConnectWise software products have landed the company on the CISA KEV catalog.


This Cyber News was published on www.securityweek.com. Publication date: Tue, 20 Feb 2024 17:43:04 +0000


Cyber News related to ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool

ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool - Enterprise IT software giant ConnectWise has released urgent patches for two critical security defects in its ScreenConnect remote desktop access product, warning there is high risk of in-the-wild exploitation. A second bug, documented as an improper ...
10 months ago Securityweek.com
Threat Brief: ConnectWise ScreenConnect Vulnerabilities - Feb. 13, 2024, ConnectWise was notified of two vulnerabilities impacting their remote desktop software application ScreenConnect. These vulnerabilities were first reported through their vulnerability disclosure channel in the ConnectWise Trust ...
10 months ago Unit42.paloaltonetworks.com
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
11 months ago Itsecurityguru.org
Detecting Vulnerability Scanning Traffic From Underground Tools Using Machine Learning - Our structured query language (SQL) injection detection model detected triggers containing unusual patterns that did not correlate to any known open-source or commercial automated vulnerability scanning tool. We have tested all malicious payloads ...
2 months ago Unit42.paloaltonetworks.com
How to conduct security patch validation and verification - Validation and verification are important steps in the security patch management lifecycle. They help to determine the impact of a patch on the security and efficiency of an organization's IT assets. Patch validation is the process of examining newly ...
8 months ago Techtarget.com
ConnectWise urges ScreenConnect admins to patch critical RCE flaw - ConnectWise warned customers to patch their ScreenConnect servers immediately against a maximum severity flaw that can be used in remote code execution attacks. This security bug is due to an authentication bypass weakness that attackers can exploit ...
10 months ago Bleepingcomputer.com
How Patch Management Software Solves the Update Problem - I've never met an IT leader who doesn't know how important patch management is. At Heimdal, we believe patch management software provides the solution to this problem. Patch management software is a technology that allows businesses to automate the ...
5 months ago Heimdalsecurity.com
Key software patch testing best practices - To ensure a predictable rollout when a patch is deployed across your network, it is important to test it first in a nonproduction environment. Companies install software and firmware patches to fix bugs, remove vulnerabilities and add new features, ...
8 months ago Techtarget.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)