Published 02/27/2024
ConnectWise ScreenConnect customers
A critical authentication bypass has been discovered in ConnectWise’s ScreenConnect, a software for remote desktop access. This exploit could allow attackers to access confidential information and critical systems without proper credentials. Once authenticated via the authentication bypass, attackers can exploit a path-traversal vulnerability to execute remote code within critical systems.
On February 19, 2024, ConnectWise released a Threat Advisory for patching multiple vulnerabilities discovered in the company’s ScreenConnect software. ScreenConnect is a remote desktop and access software that lets you connect directly to desktops, mobile devices, and more. The vulnerabilities, CVE-2024-1709 and CVE-2024-1708, were first reported on February 13th. These vulnerabilities have been classified as significantly exploitable, with CVE-2024-1709 receiving a 10.0 critical base score and CVE-2024-1708 receiving an 8.4 high base score by NIST.
The first vulnerability, CVE-2024-1709, involves authentication bypass, which is directly related to CWE-288 – Authentication Bypass Using an Alternate Path or Channel. A flaw was found in a text file named “SetupWizard.aspx”, which has the functionality of setting up the administrative user and installing a license for the system. In unpatched versions, this setup file can be accessed even after the initial setup is completed. This is accomplished by adding additional components after the legitimate URL to the SetupWizard.aspx (/SetupWizard.aspx/[anything]) and exploiting how the .NET framework handles URL paths. The code in the text file does not verify whether the ScreenConnect instance setup has already been completed, allowing anyone to open the setup wizard and overwrite the internal user database, thereby gaining administrative access (Poudel, 2024).
The second vulnerability, CVE-2024-1708, is related to CWE-22 – Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’). Although it is considered less severe, it is unlocked by CVE-2024-1079 and should not be underestimated (Team Huntress, 2024). This vulnerability involves manipulating ZIP file paths during extraction. Attackers can then modify these contents and execute malicious code (Poudel, 2024). To do this, a malicious actor needs to have both administrative credentials and create a malicious extension inside C:Program Files (x86)ScreenConnectApp_Extensions to write files anywhere within the folder (Team Huntress, 2024). Team Huntress showed that this ZipSlip attack was not necessary, as malicious actors can run code by accessing a ScreenConnect feature called “Extensions”. This could easily go unnoticed in a system, since no other extensions need to be installed (Team Huntress, 2024).
ConnectWise released a patched version of ScreenConnect on February 21st, 2024, and recommends updating all versions from 23.9.7 onward to 23.9.8 (ConnectWise, 2024). As of today, February 22nd, 2024, 3,800 instances of ScreenConnect have been identified as vulnerable and need to be updated to the latest version to prevent malicious actors from accessing the ScreenConnect environment. ConnectWise added that Cloud instances were automatically patched, whereas On-Prem partners need to install all required updates manually to remediate both vulnerabilities (ConnectWise).
CVE-2024-1709
| Type | Indicator |
| Threat Actor IP Address | 155[.]133[.]5[.]15 |
| Threat Actor IP Address | 155[.]133[.]5[.]14 |
| Threat Actor IP Address | 118[.]69[.]65[.]60 |
| Setup Wizard Sigma Rule | Sigma Rule Github Page |
| ScreenConnect New User Database XML File Modification Sigma Rule | Sigma Rule Github Page |
| Setup Wizard YARA Rule | YARA Rule Github Page |
CVE-2024-1708
| Type | Indicator |
| Threat Actor IP Address | 155[.]133[.]5[.]15 |
| Threat Actor IP Address | 155[.]133[.]5[.]14 |
| Threat Actor IP Address | 118[.]69[.]65[.]60 |
| App Extensions Directory Sigma Rule |
Sigma Rule Github Page |
Sigma rule for detecting requests made to the Setup Wizard with trailing paths (Huntress).
Sigma rule for detecting the ScreenConnect server writing to a temporary XML file (Huntress).
Setup Wizard YARA Rule for detecting Internet Information Services (IIS) log entries in reference to the SetupWizard (Huntress).
Sigma rule that alerts file modifications in the App_Extensions root directory (Huntress).
CVE-2024-1709. NIST. (n.d.-b). https://nvd.nist.gov/vuln/detail/CVE-2024-1709
CVE-2024-1708. NIST. (n.d.-a). https://nvd.nist.gov/vuln/detail/CVE-2024-1708
ConnectWise ScreenConnect 23.9.8 security fix. ConnectWise. (2024, February 19). https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
Detection guidance for ConnectWise CWE-288. Huntress. (2024a, February 20). https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
Understanding the ConnectWise screenconnect CVE-2024-1709 & CVE-2024-1708: Huntress blog. Huntress. (2024, February 21). https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
Mitre ATT&CK®. MITRE. (n.d.). https://attack.mitre.org/
Poudel, S. (2024, February 22). Unveiling the ScreenConnect authentication bypass (CVE-2024-1709 & CVE-2024-1708). Logpoint. https://www.logpoint.com/en/blog/emerging-threats/screenconnect-authentication-bypass/
Contributing Security Analysts: Alessandro Lovadina, Benjamin Price