Security professionals have observed widespread exploitation of two security weaknesses in ConnectWise ScreenConnect, a widely-used remote access solution. The exploitation activities are leading to ransomware infections and data theft among affected businesses.
Critical findings from cybersecurity experts at Mandiant highlight the widespread compromising of systems due to these exploitable bugs in the ConnectWise software. The firm shared details last Friday about the mass-exploited vulnerabilities, namely CVE-2024-1709 and CVE-2024-1708, allowing unauthorized access and remote code execution respectively.
While ConnectWise issued an alert about these vulnerabilities on February 19 and advised immediate patching, a significant number of customer systems remain unpatched and at risk, per the Shadowserver Foundation.
The team at Mandiant has seen a variety of attackers utilizing these flaws for purposes including ransomware deployment and comprehensive extortion practices.
Additionally, Finnish cybersecurity entity WithSecure reported on their blog post about widespread exploitation by cybercriminals leading to the delivery of password stealing tools, backdoors, and ransomware on vulnerable systems.
Security teams at Sophos and Huntress observed the notorious LockBit ransomware gang adopting these vulnerabilities in their latest attack vectors, as detailed in Huntress’ examination of the situation.
The number of customers or devices impacted by these vulnerabilities is currently unknown, with ConnectWise representatives refraining from comments. The extent of the issue might be significant, considering ConnectWise claims over a million clients managing in excess of 13 million devices.
When approached for a scheduled interview, ConnectWise unexpectedly canceled the engagement with their CISO Patrick Beggs, not providing reasons for the withdrawal.
Individuals impacted by the ConnectWise flaws can reach out to Carly Page via Signal at +441536 853968 or email at carly.page@techcrunch.com. TechCrunch can also be contacted through SecureDrop for secure communication.
FAQ Section
- What are the affected vulnerabilities in ConnectWise software?
- The vulnerabilities are CVE-2024-1709, an authentication bypass flaw, and CVE-2024-1708, a path traversal vulnerability that allows remote code execution.
- Has ConnectWise responded to these vulnerabilities?
- ConnectWise acknowledged the vulnerabilities on February 19 and recommended that customers apply patches. However, many systems remain unpatched.
- Who is exploiting these vulnerabilities?
- Several threat groups are exploiting these flaws, including cybercriminals deploying ransomware such as the LockBit gang.
- What actions are attackers taking upon exploiting these vulnerabilities?
- Attackers are using the vulnerabilities to deploy ransomware, password stealers, backdoors, crypto mining software, and to maintain network access.
- How to contact TechCrunch for those affected by the ConnectWise vulnerability?
- Those affected can reach out to Carly Page on Signal or via email, and also contact TechCrunch through SecureDrop.
Conclusion
The current mass-exploitation of vulnerabilities in ConnectWise ScreenConnect poses a significant threat to the cybersecurity landscape. The ease of exploiting these vulnerabilities and the subsequent deployment of ransomware highlight the urgent need for affected companies to apply the provided patches. The ongoing attacks also underscore the importance of vigilance and rapid response in the face of newly discovered software flaws. ConnectWise’s lack of detailed communication further emphasizes the responsibility of organizations to keep their systems updated and monitor for threats continuously.










































