{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/screenconnect--23.9.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2024-1709"},{"cvss":8.4,"id":"CVE-2024-1708"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend","ScreenConnect (\u003c 23.9.8)"],"_cs_severities":["critical"],"_cs_tags":["connectwise","screenconnect","authentication bypass","cve-2024-1709"],"_cs_type":"threat","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eThe ConnectWise ScreenConnect CVE-2024-1709 vulnerability allows attackers to bypass authentication and gain unauthorized administrative access. This vulnerability is actively being exploited in the wild. The primary attack vector involves sending malicious HTTP POST requests to the \u003ccode\u003eSetupWizard.aspx\u003c/code\u003e page, circumventing normal authentication procedures. Successful exploitation can lead to the creation of administrative users, granting the attacker full control over the affected ScreenConnect instance. ConnectWise has released version 23.9.8 to address this vulnerability. This vulnerability has been exploited in conjunction with CVE-2024-1708. Defenders should prioritize detection and patching of vulnerable ScreenConnect instances to prevent potential compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a vulnerable ConnectWise ScreenConnect instance.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted HTTP POST request to \u003ccode\u003e/SetupWizard.aspx/\u003c/code\u003e or \u003ccode\u003e*/SetupWizard.aspx/*\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe vulnerable ScreenConnect instance improperly handles the request, bypassing authentication checks.\u003c/li\u003e\n\u003cli\u003eThe attacker gains unauthorized access to administrative functions without valid credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a new administrative user account.\u003c/li\u003e\n\u003cli\u003eThe attacker logs in using the newly created administrative account.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages administrative privileges to execute arbitrary code on the server.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes persistence and expands their access to the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-1709 allows attackers to gain complete control over the ConnectWise ScreenConnect server. This can lead to data breaches, ransomware deployment, and further compromise of connected systems. The number of affected organizations is currently unknown. This impacts MSPs (Managed Service Providers) and their clients since ScreenConnect is used for remote support.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eConnectWise ScreenConnect Authentication Bypass\u003c/code\u003e to detect unauthorized access attempts to \u003ccode\u003eSetupWizard.aspx\u003c/code\u003e in web server logs.\u003c/li\u003e\n\u003cli\u003eUpgrade ConnectWise ScreenConnect instances to version 23.9.8 or later to patch CVE-2024-1709 (reference: ConnectWise security bulletin).\u003c/li\u003e\n\u003cli\u003eReview web server access logs for suspicious POST requests to \u003ccode\u003eSetupWizard.aspx\u003c/code\u003e (reference: references section).\u003c/li\u003e\n\u003cli\u003eEnable logging for web servers (IIS, Apache) or proxy servers and ensure the logs are ingested into your SIEM.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T13:38:06Z","date_published":"2024-03-28T10:09:22Z","id":"https://feed.craftedsignal.io/briefs/2024-03-connectwise-auth-bypass/","summary":"Exploitation of CVE-2024-1709 in ConnectWise ScreenConnect allows attackers to bypass authentication via the SetupWizard.aspx endpoint, potentially leading to unauthorized administrative access and remote code execution.","title":"ConnectWise ScreenConnect Authentication Bypass Vulnerability Exploitation","url":"https://feed.craftedsignal.io/briefs/2024-03-connectwise-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - ScreenConnect (\u003c 23.9.8)","version":"https://jsonfeed.org/version/1.1"}