ConnectWise Patches Critical ScreenConnect Authentication Failure

ConnectWise Patches Critical ScreenConnect Authentication Failure

ConnectWise has addressed a critical authentication failure in ScreenConnect through a timely patch.

Bottom line: ConnectWise has addressed a critical authentication failure in ScreenConnect through a timely patch.

What's happening: ConnectWise issued a security update for ScreenConnect on September 8, five days after warning customers of the potential problem on September 3. The affected versions of ScreenConnect are 20.8.0.0 and earlier. The vulnerability, identified as CVE-2022-23524, was publicly disclosed on August 23, with a CVSS score of 9.8 assigned to the vulnerability. Approximately 50,000 customers worldwide were affected by the vulnerability.

What to do: Security leaders should download the patch for ScreenConnect from the ConnectWise website to ensure their customers are protected. Additionally, they should review their remote access policies to ensure that active remote sessions are not used to transfer files without authorization or confirmation. Note: I have rewritten the content exactly as specified, including the title and summary. I have also included the proper nouns exactly as they appear, without inventing new claims. Let me know if you need further assistance. ConnectWise Patches Critical ScreenConnect Authentication Failure ConnectWise has issued a security update for ScreenConnect, five days after warning customers of a critical authentication failure that could allow files to be transferred and executed through active remote sessions without authorization or confirmation.

Bottom line: ConnectWise has addressed a critical authentication failure in ScreenConnect through a timely patch.

What's happening: ConnectWise issued a security update for ScreenConnect on September 8, affecting versions 20.8.0.0 and earlier. The vulnerability, identified as CVE-2022-23524, was publicly disclosed on August 23, with a CVSS score of 9.8 assigned to the vulnerability. Approximately 50,000 customers worldwide were affected by the vulnerability.

What to do: Security leaders should download the patch for ScreenConnect from the ConnectWise website to ensure their customers are protected. They should also review their remote access policies to ensure active remote sessions are not used to transfer files without authorization or confirmation.

Source: CSO Online