New ScreenConnect Flaw

Overview

ConnectWise has issued a security advisory for a newly discovered ScreenConnect Remote Access vulnerability that currently has no patch available. The flaw affects both cloud‑hosted and on‑premises deployments, and while a permanent fix is expected later this week, administrators are urged to apply temporary mitigations immediately.

Vulnerability Details

  • Unpatched flaw: Impacts file transfer behavior in ScreenConnect sessions.
  • Scope: Affects Support and Access sessions across cloud and on‑premises environments.
  • CVE status: No CVE ID has yet been assigned.
  • Risk: Potential exploitation by attackers to abuse file transfer permissions.

Temporary Mitigation Steps

Administrators should:

  1. Log in to ScreenConnect Administration.
  2. Navigate to Administration → Security → Roles.
  3. Edit user roles and check session groups with assigned permissions.
  4. In Scoped Permissions, deselect TransferFiles (or TransferFilesInSession for legacy).
  5. Save changes and repeat for all roles.

These steps disable file transfer permissions until the official patch is released.

Exposure Landscape

  • Shadowserver Foundation: Nearly 6,000 ScreenConnect instances are currently exposed online.
  • Exploitation risk: ScreenConnect vulnerabilities have historically been targeted by both ransomware gangs and state‑backed APT groups.

Historical Context

ScreenConnect has been repeatedly exploited in the past:

  • CVE‑2024‑1709: Abused by ransomware gangs and North Korea’s Kimsuky APT.
  • CVE‑2025‑3935: State‑sponsored hackers breached cloud instances via a ViewState injection bug.
  • CVE‑2026‑3564: Cryptographic signature verification vulnerability patched in March 2026.
  • CISA catalog: Since 2024, three ScreenConnect flaws have been added to the Known Exploited Vulnerabilities (KEV) list.

Defensive Guidance

Organizations should:

  • Apply mitigations immediately until the patch is released.
  • Audit exposed instances to ensure management interfaces are not publicly accessible.
  • Monitor logs for unusual file transfer activity.
  • Segment remote access to limit exposure.
  • Stay updated with ConnectWise advisories and CISA alerts.

Expert in the Cloud Insight

This advisory reinforces a recurring theme: remote access platforms are prime targets for attackers. With thousands of ScreenConnect instances exposed online, even a temporary flaw can become a gateway for ransomware or state‑sponsored intrusion. The lesson is clear: disable risky permissions, patch quickly, and restrict exposure of remote access tools to trusted networks only.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.