Remote Code Execution Vulnerability in ConnectWise Control by ConnectWise
CVE-2019-16514
7.2HIGH
Key Information:
- Vendor
Connectwise
- Status
- Vendor
- CVE Published:
- 23 January 2020
Badges
๐พ Exploit Exists
What is CVE-2019-16514?
A vulnerability exists within ConnectWise Control (formerly ScreenConnect) version 19.3.25270.7185, which permits remote code execution. This issue arises because the server allows administrative users to upload an unsigned extension ZIP file that contains executable code. Upon uploading, the server executes the code without validating its integrity, creating a pathway for attackers to exploit the system.