ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html
https://thehackernews.com/2026/04/china-linked-storm-1175-exploits-zero.html
https://thehackernews.com/2025/05/connectwise-hit-by-cyberattack-nation.html
https://github.com/chengbochuan3/CVE-Enterprise-Software
https://github.com/razureink/cve-2024-1708-connectwise_rce_reproduction
https://github.com/Teexo/ScreenConnect-CVE-2024-1709-Exploit
https://github.com/Phemz0/UDMQueries
https://github.com/tr1pl3ight/POCv2.0-for-CVE-2024-1709
https://github.com/W01fh4cker/ScreenConnect-AuthBypass-RCE
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
Published: 2024-02-21
Updated: 2026-04-28
Known Exploited Vulnerability (KEV)
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8.4
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Severity: High
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity: Critical
EPSS: 0.9549
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Concern