ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805
Key Takeaways ConnectWise has identified a critical security vulnerability, CVE-2024-46805, impacting file transfer functionality in its ScreenConnect Remote Access Support and Access sessions. Both...
Key Takeaways
- ConnectWise has identified a critical security vulnerability, CVE-2024-46805, impacting file transfer functionality in its ScreenConnect Remote Access Support and Access sessions.
- Both cloud-hosted and on-premises ScreenConnect deployments are affected.
- The vulnerability carries a CVSS score of 10.0, indicating maximum severity.
- ConnectWise has released an emergency patch for cloud environments and urges all self-hosted users to update immediately to version 23.9.10 or later.
- While the specific attack vector remains undisclosed, the potential for unauthorized file transfers poses a significant risk to managed endpoints and internal systems.
ConnectWise Issues Urgent Patch for Critical ScreenConnect Vulnerability CVE-2024-46805
ConnectWise has released an urgent patch addressing a critical security vulnerability, tracked as CVE-2024-46805, within its ScreenConnect Remote Access Support and Access sessions. The flaw, which received the highest possible CVSS score of 10.0, affects the platform’s file transfer functionality and impacts both cloud-hosted and on-premises deployments.
Table Of Content
The vendor’s advisory, initially published on September 3, 2026, alerted customers to a newly discovered security issue related to file transfer behavior. While ConnectWise initially withheld the CVE identifier and technical specifics, an emergency update has now been rolled out for cloud environments, and self-hosted users are strongly advised to update to version 23.9.10 or later.
Vulnerability Details and Impact
The vulnerability specifically targets CW Remote Access, previously known as ScreenConnect, and is confined to Support and Access sessions. ConnectWise has not yet publicly disclosed the precise technical details regarding how malicious actors could exploit this file transfer behavior, the potential attack scenarios, or whether active exploitation has been observed in the wild. However, the critical CVSS score underscores the severe risk posed by this flaw.
Remote access platforms are highly attractive targets for cybercriminals due to their direct access to managed endpoints, internal networks, and sensitive customer data. A vulnerability allowing unauthorized file transfers could enable attackers to exfiltrate data, inject malware, or escalate privileges within compromised environments.
Immediate Mitigation Steps and Official Patch
The advisory applies universally to all ScreenConnect Remote Access instances, whether deployed through ConnectWise’s cloud infrastructure or self-hosted. ConnectWise said it has now released an official patch for the underlying file-transfer behavior. Cloud environments have been updated, and self-hosted users must upgrade to version 23.9.10 or a subsequent release.
Before the official patch was available, ConnectWise had recommended interim mitigation steps, specifically restricting technician file-transfer privileges. This temporary measure aimed to reduce the attack surface by disabling the ability for technicians to transfer files through affected remote-access sessions.
Organizations that have not yet updated their self-hosted ScreenConnect instances must do so immediately. The process of applying the patch is critical for securing their environments against potential exploitation.
What You Should Do
- Upgrade Immediately: For self-hosted ScreenConnect deployments, update to version 23.9.10 or later without delay. Cloud environments should already be patched.
- Review User Roles and Permissions: Conduct a thorough review of all user roles, session groups, and file-transfer permissions within your ScreenConnect environment. Ensure that the
TransferFilesorTransferFilesInSessionpermission is disabled for any roles that do not absolutely require it. - Monitor ConnectWise Advisories: Continuously monitor the ConnectWise advisory page for any further updates, additional guidance, or details on affected versions.
- Audit Administrative Accounts: Verify that only authorized personnel have privileged roles within ScreenConnect and regularly audit these accounts.
- Monitor Activity Logs: Actively monitor remote-support activity for any unusual file-transfer attempts, unexpected changes to role permissions, or suspicious access patterns.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.