EXPOSURES › CVE-2025-3935
CVE-2025-3935
HIGH ⌖ ON CISA KEV · EXPLOITEDConnectWise ScreenConnect had remote code execution vulnerability actively exploited in the wild
ConnectWise ScreenConnect, a remote access software, had a critical vulnerability that allowed remote code execution if machine keys were compromised. This vulnerability was actively exploited, posing a significant security risk to users.
Shame score — Critical remote code execution vulnerability actively exploited in the wild
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.