CVE-2024-1709
KEV RANSOMWARECRITICAL 10.0EPSS 100.0%
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 99.98% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-02-22, used in ransomware campaigns
- Nuclei
- critical
- Published
- 2024-02-21
- Updated
- 2025-10-21
Proof-of-concept exploits (9)
- watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc75★ · 2024-02-25
- https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attac…
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-a…
- https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
- https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploit…
- HussainFathy/CVE-2024-17093★ · 2024-02-26
- cjybao/CVE-2024-1709-and-CVE-2024-17081★ · 2024-04-02
- sxyrxyy/CVE-2024-1709-ConnectWise-ScreenConnect-Authentication-Bypass1★ · 2024-03-22
- razureink/cve-2024-1708-connectwise_rce_reproduction