Authentication Vulnerability in ScreenConnect by ConnectWise
CVE-2025-14823
5.3MEDIUM
What is CVE-2025-14823?
A vulnerability exists in the ScreenConnect Certificate Signing Extension that could allow unauthenticated users to access encrypted configuration values via a client-facing endpoint. Although sensitive keys remain encrypted and secure at rest, this flaw may expose misleading encrypted data in client responses. To mitigate this issue, it is recommended that users upgrade to version 1.0.12 or higher, ensuring that all sensitive configurations are handled server-side and preventing any encrypted values from being inadvertently rendered on the client side.
Affected Version(s)
ScreenConnect ScreenConnect (all supported versions) when used with the Certificate Signing Extension versions prior to 1.0.12