ConnectWise has released software updates to address two security flaws in its ScreenConnect remote desktop and access software, including a critical bug that could enable remote code execution on affected systems.
The vulnerabilities are listed below –
The vulnerabilities are listed below –
CVE-2024-1708 (CVSS score: 8.4) – Improper limitation of a pathname to a restricted directory aka “path traversal”
CVE-2024-1709 (CVSS score: