ConnectWise Critical Vulnerability: Free Update Available

General News

Summary

The free support capped off a remarkable week as ConnectWise grappled to contain vulnerabilities with its remote-control software. ConnectWise said in its advisory that the vulnerabilities were critical ones that could allow “the ability to execute remote code or directly impact confidential data or critical systems.” The two vulnerabilities are CVE-2024-1709 (CWE-288), Authentication Bypass Using Alternate Path or Channel with a base CVSS score of 10, indicating “critical”, and CVE-2024-1708 (CWE-22), Improper Limitation of a Pathname to a Restricted Directory, (“Path Traversal”) with a base CVSS score of 8.4, considered “high priority.” On February 21, proof of concept code was released on GitHub that exploits the vulnerabilities and adds a new user to the compromised system, according to Sophos. ConnectWise updated its initial report to include observed, active exploitation of the vulnerabilities in the wild. On Feb 22, Sophos X-Ops reported through its social media handle that despite the recent law enforcement activity against the LockBit threat actor group we had observed several attacks over the preceding 24 hours that appeared to be carried out with LockBit ransomware. The sheer prevalence of this software and the access afforded by this vulnerability signals we are on the cusp of a ransomware free-for-all.” ConnectWise CISO Patrick Beggs urged on-premises partners to patch to the latest version of ScreenConnect in a LinkedIn post last week.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Software Development SaaS Cybersecurity Software

Linked Companies

ConnectWise
$100M to $250M