CVE-2024-1708

high KEV
Published 2024-02-21 · Modified 2026-04-28
CVSS v3
8.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS v2
VIR risk
9.9

Description

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

CISA KEV

Vendor
ConnectWise
Product
ScreenConnect
Due date
2026-05-12

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708

vendor Authored 2026-05-27

Vendor advisory: 9119a7d8-5eab-497f-8521-727c672e3725 — https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8

Exploits

Application impact

VendorProductVersionsFixed
connectwisescreenconnect{"endExcluding":"23.9.8"}23.9.8

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.