Overview
ConnectWise has issued a security advisory for a newly discovered ScreenConnect Remote Access vulnerability that currently has no patch available. The flaw affects both cloud‑hosted and on‑premises deployments, and while a permanent fix is expected later this week, administrators are urged to apply temporary mitigations immediately.
Vulnerability Details
- Unpatched flaw: Impacts file transfer behavior in ScreenConnect sessions.
- Scope: Affects Support and Access sessions across cloud and on‑premises environments.
- CVE status: No CVE ID has yet been assigned.
- Risk: Potential exploitation by attackers to abuse file transfer permissions.
Temporary Mitigation Steps
Administrators should:
- Log in to ScreenConnect Administration.
- Navigate to Administration → Security → Roles.
- Edit user roles and check session groups with assigned permissions.
- In Scoped Permissions, deselect TransferFiles (or TransferFilesInSession for legacy).
- Save changes and repeat for all roles.
These steps disable file transfer permissions until the official patch is released.
Exposure Landscape
- Shadowserver Foundation: Nearly 6,000 ScreenConnect instances are currently exposed online.
- Exploitation risk: ScreenConnect vulnerabilities have historically been targeted by both ransomware gangs and state‑backed APT groups.
Historical Context
ScreenConnect has been repeatedly exploited in the past:
- CVE‑2024‑1709: Abused by ransomware gangs and North Korea’s Kimsuky APT.
- CVE‑2025‑3935: State‑sponsored hackers breached cloud instances via a ViewState injection bug.
- CVE‑2026‑3564: Cryptographic signature verification vulnerability patched in March 2026.
- CISA catalog: Since 2024, three ScreenConnect flaws have been added to the Known Exploited Vulnerabilities (KEV) list.
Defensive Guidance
Organizations should:
- Apply mitigations immediately until the patch is released.
- Audit exposed instances to ensure management interfaces are not publicly accessible.
- Monitor logs for unusual file transfer activity.
- Segment remote access to limit exposure.
- Stay updated with ConnectWise advisories and CISA alerts.
Expert in the Cloud Insight
This advisory reinforces a recurring theme: remote access platforms are prime targets for attackers. With thousands of ScreenConnect instances exposed online, even a temporary flaw can become a gateway for ransomware or state‑sponsored intrusion. The lesson is clear: disable risky permissions, patch quickly, and restrict exposure of remote access tools to trusted networks only.
Leave a Reply