CVE-2024-1709ConnectWise ScreenConnect auth bypass via an alternate path
What broke
ConnectWise ScreenConnect through 23.9.7 left an alternate SetupWizard path that did not require authentication (CWE-288). An unauthenticated caller finished setup again and created an administrator. Huntress reproduced it the day of disclosure (19 February 2024). CISA added it to KEV. CVSS 10.0. CVE-2024-1708 is the companion path traversal. Together they are RCE.
Why it matters
ScreenConnect is how MSPs and internal IT remote into everything. An auth bypass there is a meta-IdP, the same class as N-able N-central and PaperCut. Exploitation started immediately. "We will patch next change window" was the wrong sentence.
What to do
- Upgrade to ScreenConnect 23.9.8 or later. If the box was internet-facing on 19-21 February 2024, rebuild it.
- Hunt for admin users created through SetupWizard, unexpected extensions, and new remote sessions.
- Take the management UI off the internet. Put it behind phishing-resistant MFA and a jump path.
After you patch
Remote management and support platforms are standing administrative access to every endpoint beneath them, which turns a single bypass into a many-customer incident.
- Revoke sessions and rotate the platform's own credentials, including agent enrolment keys.
- Review remote session logs for connections you cannot attribute to a technician.
- Look for independent egress the attacker may have added, such as new tunnel services or remote access tools on managed endpoints, because removing them from the console does not remove them from the network.
- Treat the platform as tier-zero privileged access in your access model going forward, not as IT tooling.
Sources
- NVD: CVE-2024-1709
- CISA KEV
- Huntress, "A Catastrophe For Control," February 2024
Related identity CVEs
Related on Start with Identity
- CVEJetBrains TeamCity 2024 authentication bypass, admin access
Unauthenticated attacker becomes a TeamCity administrator on on-prem instances. CVSS 9.8. Widely exploited. CISA KEV. The 2024 sequel to CVE-2023-42793, and the
- CVEFortiWeb auth bypass and path traversal, admin creation
FortiWeb authentication bypass plus path traversal that lets an attacker create an admin. CVSS 9.8. Added to CISA KEV around 14 November 2025, before the Decemb
- CVEIvanti Connect Secure authentication bypass
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclos
- BlogA CVE ID is a name. The value is knowing who the attacker becomes.
We opened a practitioner catalog of identity CVEs: what broke, why IAM teams should care, and what to do this week. Not an NVD mirror. A place to triage SAML wr
- BreachThe 2024 Snowflake customer breaches: stolen credentials meet missing MFA
A campaign against Snowflake customer tenants showed what happens when stolen credentials meet accounts without MFA: dozens of breaches, no platform vulnerabili