CVE-2024-1708 and CVE-2024-1709

A Proof of Concept developed by @watchTowr to exploit an authentication bypass to add a new administrative user in ConnectWise ScreenConnect. This is the first step in a trivial Remote Command Execution chain.

Follow the watchTowr Labs Team for our Security Research