In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.
The ScreenConnect extension subsystem did not perform proper server-side validation or verify the integrity of installed extension packages. A user with administrative privileges could install crafted or completely arbitrary extensions, bypassing trust mechanisms. Once such an extension was installed, its code was executed directly in the context of the ScreenConnect server. The issue affects only the server component — clients (host and guest) are not exposed.
An attacker with administrative access can execute arbitrary code on the server (RCE) and gain unauthorized access to application configuration data, which may lead to complete server takeover and compromise of data processed by the system.
ScreenConnect must be updated to version 25.8 or later, which introduces enhanced server-side configuration handling and extension integrity verification, ensuring installation of only trusted packages. Details available in the vendor's security bulletin: https://www.connectwise.com/company/trust/security-bulletins/screenconnect-2025.8-security-patch
ConnectWise ScreenConnect — all server versions older than 25.8. Client components (host and guest) are not vulnerable.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HConnectwise Screenconnect
APPConnectwise< 25.8.0.9438
Related vulnerabilities
Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. AS...
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an at...
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...
W wersjach ScreenConnect™ wcześniejszych niż 26.2, nieprawidłowa walidacja danych wejściowych w funkcji tworze...