Vulnerability record · CVE-2024-1708 · published 21 February 2024
CVE-2024-1708: ConnectWise ScreenConnect path traversal enabling remote code execution
Connectwise · Screenconnect
ConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidential data and critical systems. It matters because ScreenConnect is a remote-support tool, so compromise gives an attacker a foothold on managed endpoints and the systems that control them.
Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and public exploit references exist, so it is being actively exploited.
What it is
ConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidential data and critical systems. It matters because ScreenConnect is a remote-support tool, so compromise gives an attacker a foothold on managed endpoints and the systems that control them.
Impact
An attacker can run code on the affected server or reach confidential data and critical systems, potentially taking over the remote-support infrastructure and the endpoints it manages.
Attack surface
The flaw is network-reachable (AV:N) and requires high privileges (PR:H) plus user interaction (UI:R) per the CVSS vector, so it is not a simple unauthenticated hit. The description does not state the exact entry point, so defenders should treat any privileged ScreenConnect workflow as the likely path.
Exploitation
CISA added it to KEV with a due date of 2026-05-12 and flags known ransomware campaign use, and EPSS gives a 30-day probability of 0.9549 (99.867th percentile). Reference tags include Exploit, so public exploitation material exists.
What to do
- Upgrade ConnectWise ScreenConnect to 23.9.8 or later as the vendor advisory directs.
- If immediate patching is not possible, apply the vendor's stated mitigations or take the instance off the internet until it is fixed.
- Restrict ScreenConnect administrative and privileged access to trusted accounts and networks.
- Review exposed ScreenConnect instances for signs of compromise before and after patching.
- Follow BOD 22-01 guidance for cloud services if the instance is cloud-hosted.
Detection
- Hunt for path-traversal patterns such as ../ sequences in ScreenConnect web or application logs.
- Monitor for unexpected child processes or command execution spawned by the ScreenConnect service.
- Alert on unusual outbound connections or new accounts created from ScreenConnect hosts.
- Correlate ScreenConnect access logs with known exploitation indicators from the vendor and third-party advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-1708 to the Known Exploited Vulnerabilities catalog on 28 April 2026 as "ConnectWise ScreenConnect Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 | Vendor Advisory |
| https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass | ExploitThird Party Advisory |
| https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 | Vendor Advisory |
| https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708 | Third Party AdvisoryUS Government Resource |
| https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high | Technical Description |
Track CVE-2024-1708 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1708), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.