Major ScreenConnect Vulnerability Exposes Systems to Malicious Code Injection

Major ScreenConnect Vulnerability Exposes Systems to Malicious Code Injection

Critical Security Update: ScreenConnect Vulnerability Demands Immediate Action

ConnectWise has urgently rolled out a critical update for its ScreenConnect remote access platform to neutralize a newly uncovered threat that could grant attackers the ability to run malicious code on vulnerable servers.

Cataloged as CVE-2025-3935 and linked to CWE-287 (Improper Authentication), this flaw impacts all ScreenConnect releases up to version 25.2.3.

Independent researchers have determined that ScreenConnect versions up to and including 25.2.3 are vulnerable to ViewState code injection, a technique that manipulates how ASP.NET Web Forms retain state information across page requests. This flaw received a high-risk CVSS rating of 8.1 due to its potential severity.

Under normal conditions, ViewState data is Base64-encoded and secured using machine-specific keys. If attackers obtain these machine keys — particularly through elevated access — they could inject crafted ViewState payloads into unprotected ScreenConnect instances, leading to remote code execution on the affected servers.

In its advisory, ConnectWise emphasized that this weakness is not exclusive to ScreenConnect, but a broader risk across any solution relying on ASP.NET ViewState mechanisms.

Because of the active exploitation risk, ConnectWise has labeled the issue Priority 1 (High), reserved for vulnerabilities currently under attack or facing a significant threat of exploitation.

This discovery follows broader alerts from Microsoft Threat Intelligence issued in February 2025, which warned about attackers leveraging static machine keys sourced from public repositories — a departure from traditional methods of key theft via underground forums. Researchers have since uncovered more than 3,000 publicly exposed keys, amplifying the urgency.


Patch Details and Urgent Recommendations

ConnectWise addressed the issue by releasing ScreenConnect version 25.2.4 on April 24, 2025. The patch disables ViewState usage entirely, eliminating the attack vector.

  • Cloud-hosted ScreenConnect users on screenconnect.com or hostedrmm.com have already been updated and require no action.
  • On-premises ScreenConnect administrators must immediately:
    • Go to Administration > License > Version Check within their portal.
    • Install version 25.2.4 if they are running any build up to 25.2.3.
    • Renew expired licenses if necessary to access the latest security updates (free patches are also available for selected legacy versions starting from 23.9).

ConnectWise stresses that before reconnecting patched servers to production environments, administrators should conduct a full compromise assessment. If any breach indicators are discovered, organizations are advised to initiate formal incident response protocols: isolate affected systems, preserve forensic evidence, and engage cybersecurity experts if necessary.


A Pattern of Threats

This new vulnerability echoes the critical ScreenConnect exploits from early 2024 (CVE-2024-1708 and CVE-2024-1709), which were actively weaponized by ransomware groups. Although the exploitation method differs, the underlying risk remains the same: remote access software continues to be a prized target in today’s distributed workforce landscape.

Organizations still relying on unpatched instances are urged to upgrade without delay to safeguard their environments against potential attacks.

More Articles & Posts