Vulnerability record · CVE-2024-1709 · published 21 February 2024
CVE-2024-1709: ConnectWise ScreenConnect authentication bypass via alternate path
Connectwise · Screenconnect
ConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functionality through an alternate path or channel. The flaw is remotely exploitable with no privileges or user interaction, and the vendor fixed it in 23.9.8. Because ScreenConnect is widely used for remote support, a bypass exposes confidential data and critical systems directly.
Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network exploitation, active exploitation with ransomware use, and a KEV listing make this an emergency patch.
What it is
ConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functionality through an alternate path or channel. The flaw is remotely exploitable with no privileges or user interaction, and the vendor fixed it in 23.9.8. Because ScreenConnect is widely used for remote support, a bypass exposes confidential data and critical systems directly.
Impact
An attacker gains unauthenticated access to confidential information and critical systems, with the potential to reach administrative functionality and remote code execution. In practice this can lead to full control of the ScreenConnect server and any managed endpoints.
Attack surface
Reachable over the network via HTTP/HTTPS on the ScreenConnect server; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any internet-exposed or reachable ScreenConnect instance is in scope.
Exploitation
Actively exploited: CISA added it to KEV on 2024-02-22 with a 2024-02-29 due date and flagged known ransomware campaign use, and EPSS is 0.9998. Public exploit code and Metasploit modules exist per reference tags.
What to do
- Upgrade ScreenConnect to 23.9.8 or later immediately; this is the only complete fix.
- If patching cannot be done at once, follow the vendor bulletin's mitigation guidance or take the server off the internet until it is patched.
- Restrict network access to the ScreenConnect server to trusted management networks and block unnecessary public exposure.
- Audit for unauthorized accounts, especially newly created administrative users, and remove any that are not legitimate.
- Rotate credentials and secrets stored or managed through the ScreenConnect instance after patching.
Detection
- Review ScreenConnect logs for requests to unusual or alternate paths that bypass the normal login flow.
- Alert on creation of new user accounts, especially administrative accounts, outside change windows.
- Monitor for post-exploitation activity such as unexpected remote sessions, new extensions or plugins, and outbound connections from the server.
- Hunt for known exploitation indicators and IOCs published by Huntress and other referenced advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-1709 to the Known Exploited Vulnerabilities catalog on 22 February 2024 as "ConnectWise ScreenConnect Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 29 February 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-1709 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1709), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.