← Vulnerability feed

Vulnerability record · CVE-2024-1709 · published 21 February 2024

CVE-2024-1709: ConnectWise ScreenConnect authentication bypass via alternate path

Connectwise · Screenconnect

ConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functionality through an alternate path or channel. The flaw is remotely exploitable with no privileges or user interaction, and the vendor fixed it in 23.9.8. Because ScreenConnect is widely used for remote support, a bypass exposes confidential data and critical systems directly.

10.0 CVSS 3.1 Critical CISA KEV since 22 Feb 2024 Known ransomware use EPSS 100% · top 0.1% CWE-288 · Authentication bypass via alternate path
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
21References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network exploitation, active exploitation with ransomware use, and a KEV listing make this an emergency patch.

What it is

ConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functionality through an alternate path or channel. The flaw is remotely exploitable with no privileges or user interaction, and the vendor fixed it in 23.9.8. Because ScreenConnect is widely used for remote support, a bypass exposes confidential data and critical systems directly.

Impact

An attacker gains unauthenticated access to confidential information and critical systems, with the potential to reach administrative functionality and remote code execution. In practice this can lead to full control of the ScreenConnect server and any managed endpoints.

Attack surface

Reachable over the network via HTTP/HTTPS on the ScreenConnect server; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any internet-exposed or reachable ScreenConnect instance is in scope.

Exploitation

Actively exploited: CISA added it to KEV on 2024-02-22 with a 2024-02-29 due date and flagged known ransomware campaign use, and EPSS is 0.9998. Public exploit code and Metasploit modules exist per reference tags.

What to do

  • Upgrade ScreenConnect to 23.9.8 or later immediately; this is the only complete fix.
  • If patching cannot be done at once, follow the vendor bulletin's mitigation guidance or take the server off the internet until it is patched.
  • Restrict network access to the ScreenConnect server to trusted management networks and block unnecessary public exposure.
  • Audit for unauthorized accounts, especially newly created administrative users, and remove any that are not legitimate.
  • Rotate credentials and secrets stored or managed through the ScreenConnect instance after patching.

Detection

  • Review ScreenConnect logs for requests to unusual or alternate paths that bypass the normal login flow.
  • Alert on creation of new user accounts, especially administrative accounts, outside change windows.
  • Monitor for post-exploitation activity such as unexpected remote sessions, new extensions or plugins, and outbound connections from the server.
  • Hunt for known exploitation indicators and IOCs published by Huntress and other referenced advisories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-1709 to the Known Exploited Vulnerabilities catalog on 22 February 2024 as "ConnectWise ScreenConnect Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 29 February 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/rapid7/metasploit-framework/pull/18870 Issue TrackingPatchThird Party Advisory
https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc ExploitThird Party Advisory
https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exp Press/Media CoverageThird Party Advisory
https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/ Press/Media CoverageThird Party Advisory
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 Vendor Advisory
https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/ Third Party Advisory
https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass ExploitThird Party Advisory
https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2 ExploitThird Party Advisory
https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8 Third Party Advisory
https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/ Press/Media CoverageThird Party Advisory
https://github.com/rapid7/metasploit-framework/pull/18870 Issue TrackingPatchThird Party Advisory
https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc ExploitThird Party Advisory
https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exp Press/Media CoverageThird Party Advisory
https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/ Press/Media CoverageThird Party Advisory
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 Vendor Advisory
https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/ Third Party Advisory
https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass ExploitThird Party Advisory
https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2 ExploitThird Party Advisory
https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8 Third Party Advisory
https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/ Press/Media CoverageThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1709 US Government Resource

Track CVE-2024-1709 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed7.2CVE-2025-3935ScreenConnect ViewState code injection enables RCEScreenConnect 25.2.3 and earlier rely on ASP.NET ViewState protected by machine keys, and if those keys are compromised an attacker can craft a malic…KEVEPSS 3.5%analysed9.1CVE-2025-14265Connectwise screenconnect download of code without integrity check vulnerabilityIn versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation …EPSS 0.37%8.1CVE-2023-47257Connectwise automate code injection vulnerabilityConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.EPSS 1.0%5.5CVE-2023-47256Connectwise automate improper authentication vulnerabilityConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settingsEPSS 0.45%5.3CVE-2025-14823Connectwise screenconnect vulnerabilityIn deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could…EPSS 0.15%5.3CVE-2022-36781Connectwise screenconnect improper restriction of authentication attempts vulnerabilityConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate r…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2024-1709), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.