ransomware BleepingComputer / CISA Advisory

Critical ScreenConnect Remote Code Execution Flaw Actively Exploited by Ransomware Cartels

Cybersecurity authorities warn that a critical remote code execution vulnerability in ConnectWise ScreenConnect is under mass exploitation in the wild. Threat actors bypass setup authentication controls to create unauthorized administrator accounts, executing arbitrary payloads to distribute ransomware across managed service provider customer networks.

Critical ScreenConnect Remote Code Execution Flaw Actively Exploited by Ransomware Cartels

Cybersecurity authorities warn that a critical remote code execution vulnerability in ConnectWise ScreenConnect is under mass exploitation in the wild. Threat actors bypass setup authentication controls to create unauthorized administrator accounts, executing arbitrary payloads to distribute ransomware across managed service provider customer networks.

A dangerous wave of cyberattacks targeting IT service providers and corporate enterprises has erupted following confirmation that a critical vulnerability in the remote desktop and access software ConnectWise ScreenConnect is under massive in-the-wild exploitation. Threat actors, including prominent ransomware cartels, are aggressively weaponizing the flaw to bypass authentication controls, seize complete control of host servers, and execute remote commands across thousands of downstream client endpoints. The US Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency warning urging all organizations to take immediate remediation measures.

The vulnerability stems from an authentication bypass within the initialization and configuration workflow (Setup Wizard Bypass). By interacting directly with specific endpoints intended solely for initial server deployment, external unauthenticated attackers can trigger administrative account generation without supplying valid credentials. Once administrative access is achieved, attackers utilize ScreenConnect's native remote command execution capabilities (RCE) to deploy malicious scripts and secondary payloads to all managed client devices.

Because ScreenConnect is widely deployed by Managed Service Providers (MSPs), the platform functions as an unobstructed conduit into corporate networks. Threat intelligence telemetries reveal that cybercriminal groups associated with LockBit and BlackCat ransomware operations began deploying automated scanning tools within hours of technical proof-of-concept availability. Adversaries immediately establish persistence via PowerShell routines, disable endpoint defenses, and initiate mass data exfiltration preceding enterprise encryption.

Security researchers emphasize that the threat is acute even for organizations utilizing firewalls and multi-factor authentication, as ScreenConnect relay servers are frequently exposed to the public internet to enable remote administrative support. Once compromised externally, the appliance enables adversaries to bypass perimeter security layers entirely.

Action Plan for System Administrators and Service Providers

  • Apply Official ConnectWise Patches Immediately: Upgrade all on-premise ScreenConnect servers to the latest patched release without delay. While cloud-hosted instances have been patched by the vendor, administrators must verify local account rosters.
  • Audit User Management Consoles: Rigorously inspect the ScreenConnect administrative user directory. The presence of unfamiliar user accounts—particularly those mimicking legitimate technician nomenclature or containing random alphanumeric strings—indicates probable server compromise.
  • Restrict Access to Setup Endpoints: Configure perimeter firewalls or Web Application Firewalls (WAF) to block all external access to setup and configuration endpoints.
  • Isolate Suspected Instances: If anomalous commands or unauthorized users are detected, immediately disconnect the ScreenConnect server from the internal network to prevent malicious payload broadcast to client endpoints.

Digital Forensics and Indicators of Compromise

Incident response teams should execute the following verification steps:

1. Audit Session and Command Histories: Review ScreenConnect internal audit logs for commands executed via the "Run Command" or "Backstage" features over the preceding 48 hours, paying particular attention to encoded PowerShell or cmd.exe scripts retrieving external payloads. 2. Analyze Egress Connections: Inspect perimeter firewall and server connection logs for unauthorized outbound traffic from the ScreenConnect host toward unfamiliar cloud storage repositories or command-and-control IP addresses. 3. Conduct Endpoint Health Inspections: Execute comprehensive scans utilizing Endpoint Detection and Response (EDR) across all machines maintaining active ScreenConnect agents.

Sources et références

← Toutes les actualités Outils