Remote Maintenance ScreenConnect: Critical vulnerability allows code execution
heise.de·3d
🌐WASI
Preview
Report Post

In the remote maintenance software ScreenConnect from Connectwise, attackers can exploit a critical security vulnerability to install their extensions on the server. Updated software is intended to resolve the issue.

The vulnerability description states that "server-side validation and integrity checking within the extension subsystem allow the installation and execution of untrusted or arbitrary extensions by authenticated or administrative users." Abuse of this behavior could lead to the execution of custom code or unauthorized access to the app’s configuration data. "The issue exclusively affects the ScreenConnect server component; host and guest clients are not affected," the authors of the advisory clarify (CVE-2025-14265, C…

Similar Posts

Loading similar posts...