ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Summary

ConnectWise has released a patch for a vulnerability in its ScreenConnect software that attackers were exploiting to send and execute files without authorization. This flaw allowed for worm-like attacks, spreading rapidly through active remote sessions. The vulnerability enabled unauthorized file execution once an attacker gained an active remote session.

IFF Assessment

FOE

This vulnerability allows attackers to execute arbitrary code and spread through networks, posing a significant threat to defenders.

Severity

9.1 Critical (AI Estimated)

The vulnerability allows for remote code execution without authentication after initial session compromise, with a high impact on confidentiality, integrity, and availability. The attack vector is network, and the exploitability is high.

Defender Context

This incident highlights the critical need for timely patching of remote management software, as exploited vulnerabilities can lead to widespread compromise. Defenders should proactively monitor for indicators of compromise related to ScreenConnect and ensure all endpoints are updated to the patched version to prevent further exploitation.

Read Full Story →