The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that attackers are actively exploiting a critical vulnerability in ConnectWise ScreenConnect, adding it to its Known Exploited Vulnerabilities (KEV) catalog. This moves the threat from theoretical to immediate, requiring urgent action from organizations using the popular Remote Monitoring and Management (RMM) software.

Tracked as CVE-2024-1709, the authentication bypass vulnerability carries a maximum CVSS score of 10.0. It allows unauthenticated remote attackers to gain access to a ScreenConnect instance. The risk is magnified because RMM tools like ScreenConnect provide privileged, widespread control over managed endpoints, offering a direct pathway for ransomware deployment and data theft.

CISA's KEV catalog serves as a de facto prioritization list for critical vulnerabilities. While its directives are legally binding for U.S. federal agencies, the catalog is a key reference for security teams globally. Its inclusion signals that exploitation is happening and requires immediate remediation.

Immediate Mitigation Steps

For IT administrators managing ScreenConnect instances, swift action is imperative:

  1. Patch Now: Apply the latest security updates from ConnectWise without delay. This is the primary and most effective control.
  2. Audit for Breach: Scrutinize ScreenConnect logs for indicators of compromise, such as unauthorized access from unfamiliar IP addresses or anomalous administrative actions.
  3. Hunt for Signs of Intrusion: Deploy enhanced monitoring on endpoints managed by ScreenConnect. Watch for suspicious processes, unexpected network connections, or signs of lateral movement.
  4. Restrict Access Temporarily: If patching is not immediately possible, limit external access to the ScreenConnect server. Use a VPN or IP allowlists to restrict connections to only trusted sources, shrinking the attack surface.

This incident highlights the acute security risk posed by vulnerable administrative tools. Prioritizing the patch and validating system integrity are critical steps to prevent these platforms from becoming a gateway for broader network compromise.


Note for ZH_TW translation team: When localizing this article, ensure "Hunt for Signs of Intrusion" is rendered as "排查入侵情況" rather than a literal translation. Similarly, translate the headline as "緊急:Critical ScreenConnect 漏洞已證實遭積極利用,需立即進行修補" to avoid untranslated English in the title and use natural phrasing.


美國網絡安全和基礎設施安全局(CISA)已證實攻擊者正積極利用 ConnectWise ScreenConnect 中的一個關鍵漏洞,並將其列入已知被利用漏洞(KEV)目錄。此舉將威脅從理論層級提升至緊急狀況,使用該熱門遠端監控與管理(RMM)軟件的組織需立即採取行動。

此漏洞編號為 CVE-2024-1709,是一個身份驗證繞過漏洞,CVSS 評分達到最高的 10.0 分。它允許未經身份驗證的遠端攻擊者存取 ScreenConnect 實例。由於像 ScreenConnect 這類 RMM 工具對受管端點擁有特權級別的廣泛控制權,此風險被放大,為勒索軟件部署和數據竊取提供了直接途徑。

CISA 的 KEV 目錄事實上充當關鍵漏洞的優先處理清單。雖然其指令對美國聯邦機構具有法律約束力,但該目錄也是全球安全團隊的重要參考依據。其被列入意味著漏洞正在被利用,並需要立即補救。

即時緩解措施

對於管理 ScreenConnect 實例的 IT 管理員,迅速行動至關重要:

  1. 立即修補:毫不延遲地套用 ConnectWise 發布的最新安全更新。這是首要且最有效的控制措施。
  2. 審計入侵:仔細檢查 ScreenConnect 日誌,尋找入侵指標,例如來自陌生 IP 位址的未授權存取或異常管理操作。
  3. 排查入侵情況:對 ScreenConnect 管理的端點部署加強監控。留意可疑程序、意外的網絡連接或橫向移動的跡象。
  4. 臨時限制存取:若無法立即修補,請限制對 ScreenConnect 伺服器的外部存取。使用 VPN 或 IP 白名單將連接限制僅來自受信任來源,以縮小攻擊面。

此事件突顯了易受攻擊管理工具帶來的嚴重安全風險。優先進行修補並驗證系統完整性,是防止這些平台成為更廣泛網絡入侵途徑的關鍵步驟。

新聞來源 / Original News Source