---
title: ConnectWise Vulnerability Update
description: "On February 19, 2024, ConnectWise released a security bulletin reporting two vulnerabilities: CVE-2024-1709 and CVE-2024-1708. Both vulnerabilities affect the ScreenConnect On-Premise Product. Cloud-based ScreenConnect products were updated automatically by ConnectWise."
image: https://www.irongatesecurity.com/hubfs/ConnectWise.jpg
---

[Skip to the main content.](https://www.irongatesecurity.com/ironintel/connectwise-vulnerability-update#main-content)

[![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=1246&height=190&name=Plexos_IronGate_Logo_Final-2.png "Plexos_IronGate_Logo_Final-2")](https://www.irongatesecurity.com)

[![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=1246&height=190&name=Plexos_IronGate_Logo_Final-2.png "Plexos_IronGate_Logo_Final-2")](https://www.irongatesecurity.com)

- [Who We Are](https://www.irongatesecurity.com/who-we-are) 
    - [Our Leaders](https://www.irongatesecurity.com/who-we-are#our-leaders)
- [Services](https://www.irongatesecurity.com/services) 
    - [Active Defense](https://www.irongatesecurity.com/active-defense) 
          - [Governance, Risk & Compliance](https://www.irongatesecurity.com/governance-risk-compliance)
          - [Security Operation (SecOps) Services](https://www.irongatesecurity.com/security-operation-services)
    - [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response)
    - [Insurance Advisory Services](https://www.irongatesecurity.com/insurance-advisory-services)
- [Why IronGate](https://www.irongatesecurity.com/why-irongate)
- [How We Work](https://www.irongatesecurity.com/how-we-work)
- Resources 
    - [IronINTEL Blog](https://www.irongatesecurity.com/ironintel)
    - [Careers](https://www.irongatesecurity.com/careers)

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLIvK2Q%2BU7rJlKU8O%2Bn%2FhJ6afVWL1QTRNBzSq90KGbVR1aoTa%2FQtdhWbHpgo%2BCO4KigBxojUvSer4CHd7uv5b2Nw5L5C6CJ23n9UQNZOeeIYCSJGVo6SnjIg063miOs0GbzFO%2FvG9V75zuKvT06yD3kjzFBR1YTWZEOzSIM4UjDJk4Y%3D&webInteractiveContentId=129984586382&portalId=43428275)

Toggle Menu

Toggle Menu

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLIvK2Q%2BU7rJlKU8O%2Bn%2FhJ6afVWL1QTRNBzSq90KGbVR1aoTa%2FQtdhWbHpgo%2BCO4KigBxojUvSer4CHd7uv5b2Nw5L5C6CJ23n9UQNZOeeIYCSJGVo6SnjIg063miOs0GbzFO%2FvG9V75zuKvT06yD3kjzFBR1YTWZEOzSIM4UjDJk4Y%3D&webInteractiveContentId=129984586382&portalId=43428275)

- [Who We Are *Toggle Menu*](https://www.irongatesecurity.com/who-we-are) 
    - [Our Leaders](https://www.irongatesecurity.com/who-we-are#our-leaders)
- [Services *Toggle Menu*](https://www.irongatesecurity.com/services) 
    - [Active Defense *Toggle Menu*](https://www.irongatesecurity.com/active-defense) 
          - [Governance, Risk & Compliance](https://www.irongatesecurity.com/governance-risk-compliance)
          - [Security Operation (SecOps) Services](https://www.irongatesecurity.com/security-operation-services)
    - [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response)
    - [Insurance Advisory Services](https://www.irongatesecurity.com/insurance-advisory-services)
- [Why IronGate](https://www.irongatesecurity.com/why-irongate)
- [How We Work](https://www.irongatesecurity.com/how-we-work)
- Resources
  
  *Toggle Menu* 
  
    - [IronINTEL Blog](https://www.irongatesecurity.com/ironintel)
    - [Careers](https://www.irongatesecurity.com/careers)

 1 min read

# ConnectWise Vulnerability Update

[![Picture of IronGate](https://www.irongatesecurity.com/hubfs/IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate)  Feb 26, 2024, 9:42:24 AM

![ConnectWise Vulnerability Update](https://www.irongatesecurity.com/hubfs/ConnectWise.jpg)

## Vulnerable organizations should follow the recommended actions from ConnectWise, plus several other key precautions

On February 19, 2024, [ConnectWise released a security bulletin](https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8) reporting two vulnerabilities: CVE-2024-1709 and CVE-2024-1708. Both vulnerabilities affect the ScreenConnect On-Premise Product. Cloud-based ScreenConnect products were updated automatically by ConnectWise. When exploited, they allow an attacker to bypass authentication or traverse remote directories potentially accessing files. These vulnerabilities affect ScreenConnect versions 23.9.7 and prior. The Cybersecurity Infrastructure & Security Agency (CISA) added CVE-2024-1709 to the [Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) indicating this vulnerability is being exploited by adversaries. 

ConnectWise recommends the following actions to mitigate the vulnerabilities:

1. Immediately upgrade ScreenConnect to 23.9.8 or newer. 
2. For cloud-based version, verify ScreenConnect agents were upgraded automatically. 

In addition to performing the recommended actions from ConnectWise, potentially impacted organizations should take the following precautions as part of their incident response process: 

*Note: The following response steps should be performed before upgrading the vulnerable products to avoid overwriting pertinent artifacts. Once the artifacts are preserved, continue with upgrading the vulnerable products. *

1. Review ScreenConnect logs (on-prem, cloud), Firewall logs (on-prem deployments), and IIS logs for indicators of compromise (IoC). 
2. Review the User.xml file to identify anomalous activity. [According to Team Huntress](https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2), the User.xml file is overwritten whenever any user performs an action. Reliance on this file alone is not enough. Previous files could possibly be recovered through digital forensics. 
3. Review Windows Event logs for Event ID 4663. This requires Advanced Auditing to have been enabled prior to the exploit. 

IoCs reported by ConnectWise: 

- 155.133.5\[.\]15 
- 155.133.5\[.\]14 
- 118.69.65\[.\]60 

Additional steps for mitigation if abnormal access is identified:

- Isolate the ScreenConnect system from the internet and preserve it in place (do not power off).
- Contact your Digital Forensics and Incident Response provider for additional assistance. 

Additional Resources

- [NIST CVE-2024-1708](https://nvd.nist.gov/vuln/detail/CVE-2024-1708) 
- [NIST CVE-2024-1709](https://nvd.nist.gov/vuln/detail/CVE-2024-1709) 
- [Huntress Understanding the ScreenConnect Authentication Bypass](https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass) 

---

Check out IronGate’s Digital Forensics and Incident Response capabilities:

[![LEARN MORE](https://no-cache.hubspot.com/cta/default/43428275/interactive-134473575199.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLI18IYIInCntiqkoi46Wy6LycMjWycP7T0OSWHCwKv6V6mgnrvBoRgegabCr2en0Gb%2BJiwxTgZK3%2BQt1X8JabQBPFhWOmWYySysjGWhtnUvXbBWUBJQPHrh%2BmwOmrjsrWo4pv%2BIIalqi2HpL767uIdSOl%2Bu%2BBO6VZOuGcPscU1ofpRX%2BLmdarmWT%2BwTZzNpxxLrVyIHghk%2FlJh7oO4u&webInteractiveContentId=134473575199&portalId=43428275)

| ![Ramey](https://www.irongatesecurity.com/hs-fs/hubfs/Ramey.png?width=276&height=276&name=Ramey.png)   | [Steve Ramey](https://www.irongatesecurity.com/steve-ramey) has spent the past two decades helping clients protect, investigate, and respond to events involving their digital interests. He has led hundreds of data breach investigations, assessed incident response and security programs, and successfully advised organizations through extortion negotiations. |
| --- | --- |

 

<https://www.irongatesecurity.com/>

[![Citrix Zero-Day Vulnerability Update](https://www.irongatesecurity.com/hubfs/1%20(2).png)](https://www.irongatesecurity.com/ironintel/citrix-zero-day-vulnerability-update)

#### [Citrix Zero-Day Vulnerability Update](https://www.irongatesecurity.com/ironintel/citrix-zero-day-vulnerability-update)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Nov 15, 2023, 12:29:20 PM

On Oct 10, 2023, Citrix released a security bulletin for two previously unknown zero-day vulnerabilities: CVE-2023-4966 and CVE-2023-4967. These...

[Read More](https://www.irongatesecurity.com/ironintel/citrix-zero-day-vulnerability-update)

[![IronCORE Recon 2026-03-27](https://www.irongatesecurity.com/hubfs/ChatGPT%20Image%20Mar%2013%2c%202026%2c%2010_08_54%20AM.png)](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-03-27)

#### [IronCORE Recon 2026-03-27](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-03-27)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Mar 27, 2026, 11:46:39 AM

Adversaries are shifting tactics, prioritizing identity and supply chain vulnerabilities. Explore how AI is reshaping the cybersecurity landscape and...

[Vulnerability](https://www.irongatesecurity.com/ironintel/tag/vulnerability) [Ransomware](https://www.irongatesecurity.com/ironintel/tag/ransomware) [IronCORE Recon](https://www.irongatesecurity.com/ironintel/tag/ironcore-recon) [AI](https://www.irongatesecurity.com/ironintel/tag/ai) [NPM](https://www.irongatesecurity.com/ironintel/tag/npm) [phishing](https://www.irongatesecurity.com/ironintel/tag/phishing) [Quantum](https://www.irongatesecurity.com/ironintel/tag/quantum) [Zero-Day](https://www.irongatesecurity.com/ironintel/tag/zero-day)

[Read More](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-03-27)

[![IronCORE Recon 2026-04-24](https://www.irongatesecurity.com/hubfs/ChatGPT%20Image%20Mar%2013%2c%202026%2c%2010_08_54%20AM.png)](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-24)

#### [IronCORE Recon 2026-04-24](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-24)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Apr 24, 2026, 9:06:03 AM

Adversaries are shifting focus from endpoints to infrastructure and identity controls, creating new vulnerabilities that demand immediate attention...

[Vulnerability](https://www.irongatesecurity.com/ironintel/tag/vulnerability) [Ransomware](https://www.irongatesecurity.com/ironintel/tag/ransomware) [IronCORE Recon](https://www.irongatesecurity.com/ironintel/tag/ironcore-recon) [AI](https://www.irongatesecurity.com/ironintel/tag/ai) [Zero-Day](https://www.irongatesecurity.com/ironintel/tag/zero-day) [Edge](https://www.irongatesecurity.com/ironintel/tag/edge)

[Read More](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-24)

 

![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=301&height=46&name=Plexos_IronGate_Logo_Final-2.png)

![Irongate\_Award\_Logos](https://www.irongatesecurity.com/hs-fs/hubfs/Irongate_Award_Logos.png?width=557&height=210&name=Irongate_Award_Logos.png)

 

- [Privacy Policy](https://www.irongatesecurity.com/privacy-policy)
- [Terms of Use](https://www.irongatesecurity.com/terms-of-use)
- [Your Privacy Choices ![](https://www.irongatesecurity.com/hubfs/privacyoptions.png)](https://www.irongatesecurity.com/your-privacy-choices)

© 2026 IronGate Cybersecurity LLC

[*LinkedIn*](https://www.linkedin.com/company/irongate-cybersecurity-llc/?lipi=urn%3Ali%3Apage%3Ad_flagship3_search_srp_companies_load_more%3BcMuuS27qSPaVn%2BG%2BihNnZw%3D%3D)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "IronGate",
    "url" : "https://www.irongatesecurity.com/ironintel/author/irongate"
  },
  "dateModified" : "2024-02-26T14:42:24.236Z",
  "datePublished" : "2024-02-26T14:42:24.000Z",
  "headline" : "ConnectWise Vulnerability Update",
  "image" : [ "https://www.irongatesecurity.com/hubfs/ConnectWise.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.irongatesecurity.com/ironintel/connectwise-vulnerability-update",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.irongatesecurity.com/hubfs/Plexos_IronGate_Logo_Final-1.png"
    },
    "name" : "IronGate Cybersecurity LLC"
  }
}
```