Server-Side Validation Flaw in ScreenConnect by ConnectWise
CVE-2025-14265

9.1CRITICAL

Key Information:

Vendor
CVE Published:
11 December 2025

What is CVE-2025-14265?

Prior to version 25.8, ScreenConnect contained a server-side validation and integrity check flaw within its extension subsystem. This vulnerability permitted authorized or administrative users to install and execute untrusted or arbitrary extensions, potentially allowing the execution of custom code on the server and unauthorized access to application configuration data. It is important to note that this issue exclusively affects the ScreenConnect server component while leaving host and guest clients untouched. The ScreenConnect 25.8 update rectifies this vulnerability by enhancing server-side configuration handling and integrity checks, ensuring that only trusted extensions can be installed.

Affected Version(s)

ScreenConnect All versions prior to 2025.8

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.