ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool

Enterprise IT software giant ConnectWise has released urgent patches for two critical security defects in its ScreenConnect remote desktop access product, warning there is high risk of in-the-wild exploitation.
A second bug, documented as an improper limitation of a pathname to a restricted directory was also fixed and tagged with a CVSS severity score of 8.4/10. The company says the vulnerabilities were reported a week ago through its public disclosure channel but insists there is no evidence of in-the-wild exploitation.
Affected versions include ScreenConnect 23.9.7 and prior versions and the company said it is most relevant on on-prem or self-hosted customers.
The ConnectWise ScreenConnect patches come at a time when the US government is warning about critical risks associated with legitimate remote monitoring and management software.
Enterprise IT service providers use RMM applications to remotely manage client networks and endpoints, but threat actors have been caught abusing these tools to hack into companies to launch ransomware attacks.
In malicious campaigns observed in 2022, threat actors sent phishing emails to deploy legitimate RMM software such as ScreenConnect and AnyDesk on victims' systems, and abuse these for financial gain.
Security defects in ConnectWise software products have landed the company on the CISA KEV catalog.


This Cyber News was published on www.securityweek.com. Publication date: Tue, 20 Feb 2024 17:43:04 +0000


Cyber News related to ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool

15 Best Patch Management Tools - 2025 - What is Good?What Could Be Better?Comprehensive patch management for various operating systems, applications, and third-party software.It is complex for new users and requires time and training to utilize its functionalities fully.Advanced analytics ...
3 months ago Cybersecuritynews.com
ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool - Enterprise IT software giant ConnectWise has released urgent patches for two critical security defects in its ScreenConnect remote desktop access product, warning there is high risk of in-the-wild exploitation. A second bug, documented as an improper ...
1 year ago Securityweek.com
Threat Brief: ConnectWise ScreenConnect Vulnerabilities - Feb. 13, 2024, ConnectWise was notified of two vulnerabilities impacting their remote desktop software application ScreenConnect. These vulnerabilities were first reported through their vulnerability disclosure channel in the ConnectWise Trust ...
1 year ago Unit42.paloaltonetworks.com
Scam spoofs Binance website and uses TRUMP coin as lure for malware | The Record from Recorded Future News - The researchers said that if victims follow the instructions in the email and hit the download link to get the TRUMP coins, they instead install a malicious version of a remote access tool known as ConnectWise. Hackers are spreading a malicious ...
3 months ago Therecord.media
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
1 year ago Itsecurityguru.org
Detecting Vulnerability Scanning Traffic From Underground Tools Using Machine Learning - Our structured query language (SQL) injection detection model detected triggers containing unusual patterns that did not correlate to any known open-source or commercial automated vulnerability scanning tool. We have tested all malicious payloads ...
8 months ago Unit42.paloaltonetworks.com
How to conduct security patch validation and verification - Validation and verification are important steps in the security patch management lifecycle. They help to determine the impact of a patch on the security and efficiency of an organization's IT assets. Patch validation is the process of examining newly ...
1 year ago Techtarget.com
20 Best Remote Monitoring Tools - 2025 - What is Good ?What Could Be Better ?Strong abilities to keep an eye on devices and systems.Some parts may take time to figure out.It gives you tools for remote control and troubleshooting.There could be more ways to change things.Lets you automate ...
2 months ago Cybersecuritynews.com