Huntress security researchers have reproduced a proof-of-concept exploit for two critical vulnerabilities in ConnectWise ScreenConnect: CVE-2024-1709 (CWE-288, authentication bypass, CVSS 10) and CVE-2024-1708 (CWE-22, path traversal, CVSS 8.4). Over 8,800 servers were found running vulnerable versions on Censys.io. Cloud users are automatically protected, but on-premise users must immediately patch to version 23.9.8. Huntress has also deployed a temporary hotfix to over 1,000 vulnerable managed systems and issued detection guidance while urging administrators to apply the official patch as soon as possible.

2m read timeFrom huntress.com
Post cover image