Bleepingcomputer
New ScreenConnect Flaw Enables Malware Spread via Rogue Clients
Article Content
ConnectWise has identified a critical vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments. The flaw, which impacts file transfer functionality, allows attackers to deploy rogue ScreenConnect clients that spread malware to connected systems. This malware is propagated through social engineering tactics, leading to the installation of modified clients that execute VBScript files for malicious purposes. Currently, ConnectWise is working on a patch and has advised administrators to disable file transfers as a temporary mitigation measure. The vulnerability has not yet been assigned a CVE identifier, but it is being actively exploited in the wild. Cybersecurity firm Huntress has documented the attack method, which includes creating abnormal Windows Script Host processes and modifying registry keys. Administrators are urged to review audit logs and reimage compromised machines. The situation remains urgent as the exploit is confirmed to be in use.
Key Points: • ScreenConnect vulnerability affects both cloud and on-premises deployments. • Attackers use rogue clients to spread malware via social engineering. • ConnectWise recommends disabling file transfers until a patch is available.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.