CVE-2023-25718
Last modified
CVE-2023-25718 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled executable file. It is plausible that the end user may allow the download and execution of this file to proceed. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled executable file. It is plausible that the end user may allow the download and execution of this file to proceed. There are ConnectWise Control configuration options that add mitigations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Control | <= 22.9.10032 |
References
- https://www.connectwise.comProduct
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25718?
How severe is CVE-2023-25718?
How do I fix CVE-2023-25718?
Are you affected by CVE-2023-25718?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
