Skip to content
COOEY

EXPOSURES › CVE-2024-1709

CVE-2024-1709

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-02-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-1709 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedprivilege-escalation

An authentication bypass flaw in ConnectWise ScreenConnect lets attackers create admin accounts on affected devices.

An authentication bypass vulnerability in ConnectWise ScreenConnect allows attackers with network access to the management interface to create new administrator-level accounts on affected devices. This failure is critical for DIB organizations because it directly enables privilege escalation and persistent access, violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must immediately patch ScreenConnect and restrict management interface access to mitigate this exploit-in-wild threat.

Shame score — A known authentication bypass flaw was actively exploited in the wild to create admin accounts, indicating severe negligence and avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.