ConnectWise, the software company behind the widely used ScreenConnect remote access platform, has warned customers of a newly identified security vulnerability that impacts file transfer functionality. The flaw affects both cloud-hosted and on-premises deployments, and has not yet been assigned a CVE ID.
In a security advisory issued on Thursday, ConnectWise said it had identified an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. While the company continues to work on a permanent patch, it has provided temporary mitigation steps for IT administrators to block potential attacks.
The mitigation involves logging into the ScreenConnect Administration page, navigating to Administration > Security > Roles, editing user roles, and deselecting the TransferFiles permission (or TransferFilesInSession for legacy) for each session group in the Scoped Permissions window. Administrators must save changes and repeat for all roles.
ScreenConnect vulnerabilities are frequently targeted by both financially motivated and state-backed hacking groups. In 2024, ransomware gangs and the North Korean APT group Kimsuky exploited a separate ScreenConnect flaw (CVE-2024-1709) to drop malware on vulnerable systems. Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (CVE-2025-3935), gaining access to cloud-based instances of a limited number of customers.
The company has not yet provided a specific timeline for the patch but said it plans to release it later this week.