kevmap

Coverage › CVE-2024-1709

CVE-2024-1709 Unmapped

ConnectWise ScreenConnect Authentication Bypass Vulnerability

Vendor / product
ConnectWise — ScreenConnect
Description (CISA)
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
Added to KEV
2024-02-22
Due date
2024-02-29
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Known
CWE
CWE-288
CISA notes
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
https://nvd.nist.gov/vuln/detail/CVE-2024-1709
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2024-1709. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-288) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.

Sigma rules tagged with this CVE

3 rules in SigmaHQ carry the tag cve.2024-1709. These are shown as detection content for the CVE itself. Their ATT&CK tags are deliberately not rendered here: a rule author's tag is not an authoritative statement of how the vulnerability is exploited, and this page does not show techniques for unmapped entries.

Author: Matt Anderson, Andrew Schwartz, Caleb Stewart, Huntress · 2024-02-21 · logsource: product=windows category=file_event · 1a821580-588b-4323-9422-660f7e131020
Detects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions.
CVE tags: CVE-2024-1709
Author: Matt Anderson, Kris Luzadre, Andrew Schwartz, Huntress · 2024-02-20 · logsource: product=windows service=security · 4109cb6a-a4af-438a-9f0c-056abba41c6f
This detects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.
CVE tags: CVE-2024-1709
Author: Matt Anderson, Huntress · 2024-02-20 · logsource: category=webserver · d27eabad-9068-401a-b0d6-9eac744d6e67
Detects GET requests to '/SetupWizard.aspx/[anythinghere]' that indicate exploitation of the ScreenConnect vulnerability CVE-2024-1709.
CVE tags: CVE-2024-1709