← Vulnerability feed

Vulnerability record · CVE-2024-1708 · published 21 February 2024

CVE-2024-1708: ConnectWise ScreenConnect path traversal enabling remote code execution

Connectwise · Screenconnect

ConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidential data and critical systems. It matters because ScreenConnect is a remote-support tool, so compromise gives an attacker a foothold on managed endpoints and the systems that control them.

8.4 CVSS 3.1 High CISA KEV since 28 Apr 2026 Known ransomware use EPSS 95% · top 0.1% CWE-22 · Path traversal
8.4CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and public exploit references exist, so it is being actively exploited.

What it is

ConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidential data and critical systems. It matters because ScreenConnect is a remote-support tool, so compromise gives an attacker a foothold on managed endpoints and the systems that control them.

Impact

An attacker can run code on the affected server or reach confidential data and critical systems, potentially taking over the remote-support infrastructure and the endpoints it manages.

Attack surface

The flaw is network-reachable (AV:N) and requires high privileges (PR:H) plus user interaction (UI:R) per the CVSS vector, so it is not a simple unauthenticated hit. The description does not state the exact entry point, so defenders should treat any privileged ScreenConnect workflow as the likely path.

Exploitation

CISA added it to KEV with a due date of 2026-05-12 and flags known ransomware campaign use, and EPSS gives a 30-day probability of 0.9549 (99.867th percentile). Reference tags include Exploit, so public exploitation material exists.

What to do

  • Upgrade ConnectWise ScreenConnect to 23.9.8 or later as the vendor advisory directs.
  • If immediate patching is not possible, apply the vendor's stated mitigations or take the instance off the internet until it is fixed.
  • Restrict ScreenConnect administrative and privileged access to trusted accounts and networks.
  • Review exposed ScreenConnect instances for signs of compromise before and after patching.
  • Follow BOD 22-01 guidance for cloud services if the instance is cloud-hosted.

Detection

  • Hunt for path-traversal patterns such as ../ sequences in ScreenConnect web or application logs.
  • Monitor for unexpected child processes or command execution spawned by the ScreenConnect service.
  • Alert on unusual outbound connections or new accounts created from ScreenConnect hosts.
  • Correlate ScreenConnect access logs with known exploitation indicators from the vendor and third-party advisories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-1708 to the Known Exploited Vulnerabilities catalog on 28 April 2026 as "ConnectWise ScreenConnect Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1708 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-1709ConnectWise ScreenConnect authentication bypass via alternate pathConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functio…KEVEPSS 100%analysed9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed7.2CVE-2025-3935ScreenConnect ViewState code injection enables RCEScreenConnect 25.2.3 and earlier rely on ASP.NET ViewState protected by machine keys, and if those keys are compromised an attacker can craft a malic…KEVEPSS 3.5%analysed9.1CVE-2025-14265Connectwise screenconnect download of code without integrity check vulnerabilityIn versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation …EPSS 0.37%8.1CVE-2023-47257Connectwise automate code injection vulnerabilityConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.EPSS 1.0%5.5CVE-2023-47256Connectwise automate improper authentication vulnerabilityConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settingsEPSS 0.45%5.3CVE-2025-14823Connectwise screenconnect vulnerabilityIn deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could…EPSS 0.15%5.3CVE-2022-36781Connectwise screenconnect improper restriction of authentication attempts vulnerabilityConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate r…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2024-1708), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.