Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-25718

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled executable file. It is plausible that the end user may allow the download and execution of this file to proceed. There are ConnectWise Control configuration options that add mitigations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-25718
  • Connectwise » Control » Version: 19.3.25270.7185
    cpe:2.3:a:connectwise:control:19.3.25270.7185
  • Connectwise » Control » Version: 22.9.10032
    cpe:2.3:a:connectwise:control:22.9.10032


Contact Us

Shodan ® - All rights reserved