ConnectWise ScreenConnect
cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*
- < 26.1
A vulnerability in ConnectWise ScreenConnect prior to version 26.1 allows unauthorized access, including elevated privileges, by exploiting server-level cryptographic material used for authentication. Earlier versions stored unique machine keys in server configuration files, which could be extracted and misused for session authentication. The vulnerability arises in scenarios where server integrity may be compromised.
Exploitation of this vulnerability could lead to unauthorized access and elevated privileges within the ScreenConnect application.
Users are advised to upgrade to ScreenConnect version 26.1. For on-premises installations, this version is available on the ScreenConnect Download page. Partners using an on-premises ScreenConnect installation integrated with ConnectWise Automate can access the update through the Automate Product Updates page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.