Authentication Vulnerability in ScreenConnect by ConnectWise
CVE-2025-14823
What is CVE-2025-14823?
A vulnerability exists in the ScreenConnect Certificate Signing Extension that could allow unauthenticated users to access encrypted configuration values via a client-facing endpoint. Although sensitive keys remain encrypted and secure at rest, this flaw may expose misleading encrypted data in client responses. To mitigate this issue, it is recommended that users upgrade to version 1.0.12 or higher, ensuring that all sensitive configurations are handled server-side and preventing any encrypted values from being inadvertently rendered on the client side.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ScreenConnect ScreenConnect (all supported versions) when used with the Certificate Signing Extension versions prior to 1.0.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved