Remote Code Execution Vulnerability in ConnectWise ScreenConnect
CVE-2023-47257

8.1HIGH

Key Information:

Vendor
CVE Published:
1 February 2024

What is CVE-2023-47257?

ConnectWise ScreenConnect versions up to 23.8.4 are susceptible to a vulnerability that enables man-in-the-middle attackers to execute arbitrary code by sending specially crafted messages. This flaw poses a significant risk to users, as it allows unauthorized control over affected systems. Ensuring timely updates and applying security patches are critical for protecting sensitive environments against this exploitation.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.