ConnectWise has identified a new security flaw in its ScreenConnect Remote Access platform. While a permanent patch is pending, immediate mitigation steps have been issued for IT administrators.
In a critical security advisory, ConnectWise has alerted users to a new vulnerability within its ScreenConnect Remote Access platform. The flaw specifically targets the file transfer behavior during remote sessions, potentially allowing unauthorized data movement. As of now, the vulnerability lacks a formal CVE ID, making standardized tracking difficult for many security teams.
ScreenConnect is a cornerstone tool for Managed Service Providers (MSPs) and enterprise IT departments, used globally for system maintenance and troubleshooting. Because of its high-level access privileges, any compromise in its security architecture can lead to catastrophic network breaches.
Why This Matters
BozokMedia analysis shows that remote access software remains one of the most lucrative targets for both financially motivated ransomware gangs and sophisticated state-sponsored actors. The stakes are exceptionally high, as seen in previous exploits where attackers bypassed traditional defenses once they gained valid credentials.
The lack of a CVE ID at this stage underscores the urgency for administrators to rely on manual mitigation rather than automated patch management.
Currently, the security watchdog Shadowserver is tracking nearly 6,000 ScreenConnect instances exposed to the internet. While it is unclear how many of these are active targets, the historical context of ScreenConnect exploits suggests a high risk of exploitation by groups like the North Korean Kimsuky APT.
Historical Context of Vulnerabilities
ScreenConnect has faced a series of high-profile security challenges in recent years. In 2024, the CVE-2024-1709 vulnerability was widely exploited by ransomware groups. Furthermore, a high-severity ViewState code injection bug (CVE-2025-3935) previously allowed state-sponsored hackers to breach cloud-based instances. The U.S. CISA has consistently flagged ScreenConnect vulnerabilities as being actively exploited in the wild.
Frequently Asked Questions
1. What is the recommended immediate action for administrators?
Administrators should navigate to Administration > Security > Roles and deselect the 'TransferFiles' permission for all session groups.
2. When will a permanent fix be available?
ConnectWise has indicated that a formal patch is expected to be released later this week.