CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-14265

CVSS 9.1v3.1pub. 2025-12-11upd. 2026-01-16

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.

🤖 AI Analysis
How it works

The ScreenConnect extension subsystem did not perform proper server-side validation or verify the integrity of installed extension packages. A user with administrative privileges could install crafted or completely arbitrary extensions, bypassing trust mechanisms. Once such an extension was installed, its code was executed directly in the context of the ScreenConnect server. The issue affects only the server component — clients (host and guest) are not exposed.

Impact

An attacker with administrative access can execute arbitrary code on the server (RCE) and gain unauthorized access to application configuration data, which may lead to complete server takeover and compromise of data processed by the system.

Mitigation & patch

ScreenConnect must be updated to version 25.8 or later, which introduces enhanced server-side configuration handling and extension integrity verification, ensuring installation of only trusted packages. Details available in the vendor's security bulletin: https://www.connectwise.com/company/trust/security-bulletins/screenconnect-2025.8-security-patch

Who is affected

ConnectWise ScreenConnect — all server versions older than 25.8. Client components (host and guest) are not vulnerable.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Connectwise Screenconnect

    APP
    Connectwise
    < 25.8.0.9438
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-1709CRITICAL10.0⚠ KEVPL ✓same product

Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów

CVE-2025-3935HIGH8.1⚠ KEVsame product

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. AS...

CVE-2024-1708HIGH8.4⚠ KEVsame product

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an at...

CVE-2023-47257HIGH8.1same product

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...

CVE-2026-11596MEDIUM4.7same product

W wersjach ScreenConnect™ wcześniejszych niż 26.2, nieprawidłowa walidacja danych wejściowych w funkcji tworze...