GHSA-6w2p-cgh8-m9q9
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
The cryptographic code signing process and controls on ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect) are cryptographically flawed. An attacker can remotely generate or locally alter file contents and bypass code-signing controls. This can be used to execute code as a trusted application provider, escalate privileges, or execute arbitrary commands in the context of the user. The attacker tampers with a trusted, signed executable in transit.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 2, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.