CISA Adds ConnectWise ScreenConnect and Microsoft Windows Vulnerabilities to KEV Catalog
Patch: update ConnectWise ScreenConnect to the latest version to fix CVE‑2024‑1708.
Patch: update ConnectWise ScreenConnect immediately.
Summary
CISA added two security flaws to its Known Exploited Vulnerabilities catalog, one affecting ConnectWise ScreenConnect and the other affecting Microsoft Windows. The ConnectWise vulnerability, CVE‑2024‑1708, is a path traversal flaw with a CVSS score of 8.4 that can allow attackers to read arbitrary files. Evidence of active exploitation has been reported in the wild. The Windows flaw also has a high severity rating, though the specific details are not disclosed. Both vulnerabilities were discovered by security researchers and have been patched by the vendors. CISA recommends immediate patching of affected systems. The incidents highlight the ongoing risk of software supply chain attacks. Administrators should verify that their ConnectWise and Windows installations are up to date.
Key changes
- CVE‑2024‑1708 path traversal in ConnectWise ScreenConnect
- CVSS score 8.4
- Evidence of active exploitation
- Microsoft Windows vulnerability also present
- Both vulnerabilities patched by vendors