Unpatched Flaws Could Leave ConnectWise MSPs at Risk
Summary
Last year, researchers from Bishopfox found eight vulnerabilities in the ConnectWise client, reported them to the company, and received the threat of a defamation lawsuit in response. Nowadays reflected XSS flaws seem more common and require user interaction (clicking a specially crafted link) to succeed. Making a request to cloud.screenconnect.com/scripts/Service/GetScripts with the correct instance ID returns information about the account including the email address and zip code that could help an attacker identify security programs used by the MSP and bypass them. ConnectWise patched this by removing the email addresses and zip codes from the response, but adversaries can still enumerate the IDs and perhaps use then later for other malicious purposes. We also recommend you implement some type of web filtering solution to block malicious sites, ensure your antivirus is up to date, and enable MFA.