Cybersecurity Threat Advisory: ScreenConnect file-transfer issue

Cybersecurity Threat Advisory

Cybersecurity Threat AdvisoryConnectWise has issued a security advisory for an undisclosed file-transfer issue affecting ScreenConnect cloud-hosted and on-premises deployments. The company recommends immediate temporary mitigations while it develops a permanent fix and awaits a CVE assignment.

What is the threat?

This issue affects file-transfer behavior in ScreenConnect Remote Access Support and Access sessions and could expose organizations to risk through the platform’s technician file-transfer functionality. While ConnectWise has not disclosed technical details about the root cause, it has provided interim guidance to reduce exposure. Specifically, organizations should remove file-transfer permissions from technician roles until a permanent fix becomes available.

Why is it noteworthy?

Remote management platforms such as ScreenConnect often have privileged access to multiple endpoints and customer environments. As a result, vulnerabilities involving file movement can create significant security risks.

ConnectWise also notes that threat actors have previously targeted ScreenConnect vulnerabilities, including campaigns linked to ransomware operators and state-sponsored groups. In addition, Shadowserver tracks nearly 6,000 internet-exposed ScreenConnect instances, increasing the potential for opportunistic exploitation if file-transfer permissions remain enabled.

What is the exposure or risk?

Organizations face exposure when ScreenConnect technician roles retain file-transfer permissions for Support and Access sessions. Threat actors could potentially leverage these permissions to move malicious or sensitive files during remote sessions.

Until ConnectWise releases a permanent fix, organizations face increased risk of unauthorized file movement and follow-on compromise activity across managed environments. The risk is particularly high in environments where technician accounts have broad privileges.

What are the recommendations?

Barracuda recommends the following actions to reduce risk:

  • Implement ConnectWise’s interim mitigation immediately: Remove the TransferFiles permission, or TransferFilesInSession for legacy roles, from relevant session groups under Administration > Security > Roles. Apply the changes across all applicable roles.
  • Review all ScreenConnect deployments: Verify both cloud-hosted and on-premises instances. Identify and remediate technician roles that retain file-transfer permissions.
  • Monitor for suspicious file-transfer activity: Review ScreenConnect administrative actions and investigate recent Support and Access session file transfers for unusual behavior, especially in highly privileged environments.
  • Prepare to deploy the permanent fix: Monitor the ConnectWise advisory for updated guidance, CVE details, and patched releases as they become available.
  • Minimize operational disruption: Identify technician workflows that depend on transferring tools, scripts, logs, or packages. Establish approved alternatives until ConnectWise releases and validates a permanent fix.

References

For more in-depth information about the recommendations, please visit the following links:

If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.

This post originally appeared on Smarter MSP.