Feb. 20, 2024, 10:38 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

ConnectWise has released software updates to address two security flaws in its ScreenConnect remote desktop and access software, including a critical bug that could enable remote code execution on affected systems.
The vulnerabilities, which currently lack CVE identifiers, are listed below -

Authentication bypass using an alternate path or channel (CVSS score: 10.0)
Improper limitation of

access address alternate authentication authentication bypass bug bypass channel code code execution connectwise critical cve desktop enable flaws found patch path remote code remote code execution remote desktop screenconnect security security flaws software software updates systems updates vulnerabilities

Senior Security Engineer - Detection and Response

@ Fastly, Inc. | US (Remote)

Application Security Engineer

@ Solidigm | Zapopan, Mexico

Defensive Cyber Operations Engineer-Mid

@ ISYS Technologies | Aurora, CO, United States

Manager, Information Security GRC

@ OneTrust | Atlanta, Georgia

Senior Information Security Analyst | IAM

@ EBANX | Curitiba or São Paulo

Senior Information Security Engineer, Cloud Vulnerability Research

@ Google | New York City, USA; New York, USA