ConnectWise Warns of Unpatched ScreenConnect Vulnerability, Provides Temporary Mitigation

Remote access flaw affects file transfer in cloud and on-premises deployments; patch expected later this week

edit
By LineZotpaper
Published
Read Time2 min
ConnectWise has disclosed a new security flaw in its ScreenConnect remote access platform that affects file transfer behavior in support and access sessions, with no patch yet available. The company has issued temporary mitigation steps while it works on a fix. Internet security watchdog Shadowserver currently tracks nearly 6,000 ScreenConnect instances exposed online, though it is unclear how many are honeypots or already secured.

ConnectWise, the software company behind the widely used ScreenConnect remote access platform, has warned customers of a newly identified security vulnerability that impacts file transfer functionality. The flaw affects both cloud-hosted and on-premises deployments, and has not yet been assigned a CVE ID.

In a security advisory issued on Thursday, ConnectWise said it had identified an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. While the company continues to work on a permanent patch, it has provided temporary mitigation steps for IT administrators to block potential attacks.

The mitigation involves logging into the ScreenConnect Administration page, navigating to Administration > Security > Roles, editing user roles, and deselecting the TransferFiles permission (or TransferFilesInSession for legacy) for each session group in the Scoped Permissions window. Administrators must save changes and repeat for all roles.

ScreenConnect vulnerabilities are frequently targeted by both financially motivated and state-backed hacking groups. In 2024, ransomware gangs and the North Korean APT group Kimsuky exploited a separate ScreenConnect flaw (CVE-2024-1709) to drop malware on vulnerable systems. Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (CVE-2025-3935), gaining access to cloud-based instances of a limited number of customers.

The company has not yet provided a specific timeline for the patch but said it plans to release it later this week.

§

Analysis

Why This Matters

  • ScreenConnect is a critical remote access tool for managed service providers (MSPs) and IT teams; an unpatched flaw could be exploited to breach networks.
  • Past ScreenConnect vulnerabilities have been actively used by ransomware groups and state-sponsored hackers, increasing the urgency for mitigation.
  • Nearly 6,000 instances remain exposed online, representing a substantial attack surface if exploitation begins before a patch is applied.

Background

ScreenConnect is an on-premises or cloud-hosted remote access platform commonly used by MSPs, IT departments, and support teams for troubleshooting, patching, and system maintenance. The platform has been a target for cyberattacks in recent years, with previous flaws exploited by both criminal ransomware gangs and advanced persistent threat (APT) groups. ConnectWise has had to address multiple security issues, including a critical ViewState code injection bug (CVE-2025-3935) last year that was linked to state-sponsored intrusions.

Key Perspectives

ConnectWise: The company has acknowledged the issue and provided clear mitigation steps while developing a permanent patch, urging administrators to act quickly. IT Administrators and MSPs: They face the challenge of balancing operational needs with security, as disabling file transfer permissions may impact legitimate remote support workflows. Attackers: Given the history of ScreenConnect being targeted, threat actors are likely scanning for vulnerable instances and may attempt to exploit the flaw before a patch is released.

What to Watch

  • Release of the official patch later this week and whether it addresses all possible attack vectors.
  • Reports of active exploitation from security vendors or Shadowserver tracking changes in exposed instance counts.
  • Any new CVE ID assignment and severity rating for the vulnerability.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.