Back to Labs
Security Advisory

CVE-2024-1709

About

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel

vulnerability, which may allow an attacker direct access to confidential information or

critical systems.

Weakness (CWE):CWE-288

Rainforest analyst review

ConnectWise ScreenConnect leaves its initial setup wizard reachable through an alternate request path even after the server has been configured. By hitting that path, an unauthenticated attacker re-triggers first-run setup and creates a brand-new administrator account on a live, already-provisioned server — handing themselves full admin access with no credentials. In practice it was paired with a companion path-traversal flaw (CVE-2024-1708) to write files and stand up code execution.

ScreenConnect is remote-management software, so control of the server is control of every endpoint it manages: an attacker can push their own code to all connected machines at once, a supply-chain-scale blast radius. The flaw was trivially exploitable and was mass-exploited within days of disclosure in February 2024, including by ransomware affiliates and nation-state actors. Patch immediately, and because the setup abuse creates persistent artifacts, audit for unrecognized administrator accounts and review what was deployed to managed agents rather than assuming the update alone is remediation.

References

Related CVEs

Frequently asked questions

What is CVE-2024-1709?

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

How severe is CVE-2024-1709?

CVE-2024-1709 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2024-1709 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2024-1709?

Public advisories list the following as affected: screenconnect. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-1709?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email