High Known exploited (KEV) Ransomware use CVE-2024-1708

Path traversal in ConnectWise ScreenConnect (CVE-2024-1708) — remote code execution, ransomware use confirmed

ConnectWise ScreenConnect Added to KEV Apr 28, 2026 Federal remediation due 2026-05-12

ConnectWise ScreenConnect, a remote-management (RMM) / remote-support tool, has a path-traversal vulnerability that could let an attacker execute remote code or directly impact confidential data and critical systems. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 8.4 High).

Key facts

  • CVE IDCVE-2024-1708
  • CVSS base score8.4 HIGH
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
  • Affected (vendor / product)ConnectWise ScreenConnect
  • CWECWE-22
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-05-12 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Path traversal (CWE-22) in ConnectWise ScreenConnect (an RMM tool that remotely manages many endpoints)
  • Can lead to remote code execution (RCE) or direct impact on confidential data and critical systems
  • RMM compromise = a "lever" to push malware to many managed endpoints at once
  • Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 8.4 High)
  • Response: update to a fixed version (internet-exposed servers first), hunt for compromise, check endpoints
  • A breach of an RMM server reaches many endpoints at once and can spread through an MSP into customer organisations.

1ScreenConnect as an RMM tool

CVE-2024-1708 is a path-traversal vulnerability (CWE-22: improper limitation of a pathname) in ConnectWise ScreenConnect (an RMM — Remote Monitoring and Management — tool used by IT administrators and MSPs to remotely manage and support many endpoints). It is listed in CISA's KEV catalog, with ransomware use confirmed.

2Remote code execution as the outcome

Per NVD, an attacker could exploit it to execute remote code (RCE) or directly impact confidential data and critical systems. RMM tools are dangerous precisely because, by nature, they hold powerful privileges to remotely operate the many endpoints under their management. If a ScreenConnect server is compromised, an attacker can use it as a base to push malware to many managed endpoints at once.

Indeed, this vulnerability is known to have been widely exploited in ransomware attacks after disclosure (CISA also confirms ransomware use).

3How RMM amplifies an intrusion

RMM run at the perimeter or as SaaS can be a "lever" that amplifies damage in a supply-chain-like fashion.

4It does not end with one machine

An RMM tool is dangerous because, by its nature, it holds strong privileges to operate many endpoints remotely. How far a breach spreads differs from an ordinary server.

When an ordinary server is breachedWhen an RMM server is breached
Information on that one machine is exposedMany endpoints beneath it are exposed at once
Damage stays inside the organisationIt can spread through an MSP into customer organisations
Recovery is confined to that machineWhat was distributed has to be traced across every endpoint
It serves as an entry pointThe distribution mechanism itself becomes the attacker's tool

This vulnerability is known to have been widely used in ransomware attacks after disclosure. An RMM run at the perimeter or as SaaS becomes a lever that widens damage in a supply-chain fashion. Updating public servers first, investigating indicators of compromise such as suspicious connections and distributions, and checking managed endpoints are all recommended.

Why it matters

A case where compromising an RMM (remote-management) tool directly enables a simultaneous attack on many managed endpoints, and was abused by ransomware. MSPs and IT teams should prioritize prompt RMM updates, minimized exposure, and compromise hunting. It shows the risk of supply-chain-like damage amplification.

FAQ

What is an RMM tool?
A tool IT administrators and MSPs use to remotely monitor, manage, and support many endpoints. Because it holds powerful remote-control privileges, a compromise has large impact.
Why is it targeted by ransomware?
Taking over an RMM lets an attacker push malware to many managed endpoints at once — a "lever" to amplify damage rapidly.
What should I do?
Update to a fixed version per ConnectWise's instructions, prioritizing internet-exposed servers, and investigate signs of compromise while checking managed endpoints.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#ConnectWise#ScreenConnect#RMM#Path traversal#Ransomware
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.