Attackers spread malware through ScreenConnect file transfers

ConnectWise has issued an advisory regarding a file transfer vulnerability in its ScreenConnect remote support software that attackers are exploiting to distribute malware. The company recommends that administrators disable file transfer permissions until an official patch is released.
Why it matters
Remote monitoring and management (RMM) tools are high-value targets for cybercriminals; securing them is essential for protecting enterprise and MSP networks.
Attackers use rogue ScreenConnect clients to spread malware A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed.
“A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory.
ScreenConnect is a popular remote support and access solution tailored for IT departments and managed service providers (MSPs). The platform can be hosted by ConnectWise (in their cloud) or self-hosted by organizations (on-prem or in their own private cloud).
Until a fix is available, ConnectWise recommends that partners disable file transfers for technicians.
Administrators can do this by going to Administration > Security > Roles , editing each assigned role, and reviewing the permissions for each session group. If TransferFiles, or TransferFilesInSession on legacy versions, is enabled, it should be deselected. The change must be applied to each applicable role.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in