Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers

Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from the possible consequences of a significant cyber-attack.
ConnectWise ScreenConnect is a remote-control software used by IT managed service providers globally.
Had Gotham Security not stepped in and had a hacker identified the vulnerabilities as part of a zero-day attack, it would likely have led to MSPs and their clients being exposed to this zero-day vulnerability.
If the vulnerabilities were left unaddressed, bad actors would have been able to gain access to all workstations and servers with ScreenConnect from a local network and then escalate their privileges to be local administrators on the affected systems.
Gotham Security acted quickly to mitigate this possibility, rapidly developing a technical write-up about the vulnerabilities and disclosing it to ConnectWise in accordance with its Vulnerability Disclosure Policy.
Within an hour of submission, ConnectWise had triaged the vulnerabilities and assigned security engineers to replicate Gotham Security's findings.
Later that same day, both findings were confirmed as valid.
ConnectWise then initiated the development of a security patch to address both vulnerabilities.
Gotham has demonstrated a unique capability in uncovering vulnerabilities at a speed that other boutique providers would struggle to match.
For more details of the ScreenConnect vulnerability and how it was addressed, please visit Discovering ConnectWise ScreenConnect RCE & LPE Vulnerabilities.


This Cyber News was published on www.itsecurityguru.org. Publication date: Thu, 11 Jan 2024 15:13:03 +0000


Cyber News related to Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers

Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers - Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from ...
5 months ago Itsecurityguru.org
ConnectWise urges ScreenConnect admins to patch critical RCE flaw - ConnectWise warned customers to patch their ScreenConnect servers immediately against a maximum severity flaw that can be used in remote code execution attacks. This security bug is due to an authentication bypass weakness that attackers can exploit ...
4 months ago Bleepingcomputer.com
Threat Brief: ConnectWise ScreenConnect Vulnerabilities - Feb. 13, 2024, ConnectWise was notified of two vulnerabilities impacting their remote desktop software application ScreenConnect. These vulnerabilities were first reported through their vulnerability disclosure channel in the ConnectWise Trust ...
4 months ago Unit42.paloaltonetworks.com
LockBit attacks continue via ConnectWise ScreenConnect flaws - Exploitation of two critical ConnectWise vulnerabilities continues to mount, with many attacks attributed to ransomware gangs such as LockBit. Last month, ConnectWise disclosed an authentication bypass vulnerability, tracked as CVE-2024-1708, that ...
3 months ago Techtarget.com
ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool - Enterprise IT software giant ConnectWise has released urgent patches for two critical security defects in its ScreenConnect remote desktop access product, warning there is high risk of in-the-wild exploitation. A second bug, documented as an improper ...
4 months ago Securityweek.com
Hackers breach healthcare orgs via ScreenConnect remote access - Security researchers are warning that hackers are targeting multiple healthcare organizations in the U.S. by abusing the ScreenConnect remote access tool. Threat actors are leveraging local ScreenConnect instances used by Transaction Data Systems, a ...
7 months ago Bleepingcomputer.com
Researchers Uncover Simple Technique to Extract ChatGPT Training Data - Can getting ChatGPT to repeat the same word over and over again cause it to regurgitate large amounts of its training data, including personally identifiable information and other data scraped from the Web? The answer is an emphatic yes, according to ...
7 months ago Darkreading.com
Researchers extract RSA keys from SSH server signing errors - A team of academic researchers from universities in California and Massachusetts demonstrated that it's possible under certain conditions for passive network attackers to retrieve secret RSA keys from naturally occurring errors leading to failed SSH ...
7 months ago Bleepingcomputer.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)