ConnectWise confirmed active exploitation of two critical vulnerabilities in ScreenConnect affecting versions earlier than 23.9.8, led by CVE-2024-1709, an authentication bypass rated CVSS 10.0, and CVE-2024-1708, a path traversal flaw. Researchers reported that attackers could reach the setup wizard, overwrite the internal user database, create administrator accounts, and then abuse the product’s extension mechanism to execute code on the host, including SYSTEM-level remote code execution. ConnectWise said its incident response team had validated compromises, while cloud-hosted instances were updated automatically and on-premises or self-hosted customers were told to upgrade immediately.
Huntress and Rapid7 published technical details showing exploitation was straightforward and urgent, increasing the risk to unpatched systems within hours of disclosure. Huntress said suspicious activity could include unusual requests to SetupWizard.aspx with trailing path segments and unexpected file changes in the App_Extensions directory, where malicious extensions may be planted for persistence or code execution. The vendor’s emergency fix in ScreenConnect 23.9.8 closed both flaws, but the rapid weaponization highlighted the exposure of remote management platforms widely used by enterprises and managed service providers.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Mnemonic SOC reported ransomware deployment through compromised ScreenConnect instances, showing the vulnerabilities were being used not just for access and persistence but for follow-on ransomware attacks. The advisory also noted multiple in-the-wild exploit cases tied to the flaws.
On February 19, 2024, ConnectWise published a security advisory for two critical ScreenConnect vulnerabilities, CVE-2024-1709 and CVE-2024-1708, affecting versions below 23.9.8. The company released ScreenConnect 23.9.8 to patch the issues, automatically updated cloud instances, and told on-premises customers to update manually.
ConnectWise released three IP addresses that it said were used by malicious actors to compromise ScreenConnect accounts. It also advised customers to hunt for related indicators of infection in their environments.
Rapid7 added an unauthenticated remote code execution exploit module for the ScreenConnect issue to Metasploit, showing that attackers could create a new administrator account and then upload a malicious extension to run a payload. The release of exploit tooling increased the urgency for defenders to patch exposed systems.
Less than 24 hours after releasing emergency patches, ConnectWise said it had received reports of compromised accounts that its incident response team investigated and confirmed, establishing that the ScreenConnect vulnerabilities were being exploited in the wild. The company urged customers, especially self-hosted and on-premises users, to upgrade immediately and hunt for signs of compromise.
Huntress recreated a proof-of-concept exploit for the ScreenConnect vulnerabilities and explained how attackers could use the authentication bypass to create an administrator account and then gain SYSTEM-level remote code execution through malicious extensions. The company also published Sigma and YARA detection rules and indicators of compromise for defenders.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
mnemonic.io
Open sourcesecurityweek.com
Open sourcehuntress.com
Open sourceconnectwise.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.