Sploitus

Exploit for Path Traversal in Connectwise Screenconnect

githubexploit · 2024-02-21

Exploit Code

README13 lines
## https://sploitus.com/exploit?id=807AB18B-3E55-5F98-A7E2-FBDDE7D1D9AC
# CVE-2024-1708 and CVE-2024-1709

A Proof of Concept developed by @watchTowr to exploit an authentication bypass to add a new administrative user in ConnectWise ScreenConnect. This is the first step in a trivial Remote Command Execution chain.

# Follow the [watchTowr](http://watchTowr.com) Labs Team for our Security Research

- https://labs.watchtowr.com/
- https://twitter.com/watchtowrcyber
- https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/
- https://www.bleepingcomputer.com/news/security/screenconnect-critical-bug-now-under-attack-as-exploit-code-emerges/
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
- Metasploit RCE module - https://github.com/rapid7/metasploit-framework/pull/18870