Share This:

Cybersecurity Threat AdvisoryConnectWise has issued a security advisory for an undisclosed file-transfer issue affecting ScreenConnect cloud-hosted and on-premises deployments. The company recommends immediate temporary mitigations while it develops a permanent fix and awaits a CVE assignment.

What is the threat?

This issue affects file-transfer behavior in ScreenConnect Remote Access Support and Access sessions and could expose organizations to risk through the platform’s technician file-transfer functionality. While ConnectWise has not disclosed technical details about the root cause, it has provided interim guidance to reduce exposure. Specifically, organizations should remove file-transfer permissions from technician roles until a permanent fix becomes available.

Why is it noteworthy?

Remote management platforms such as ScreenConnect often have privileged access to multiple endpoints and customer environments. As a result, vulnerabilities involving file movement can create significant security risks.

ConnectWise also notes that threat actors have previously targeted ScreenConnect vulnerabilities, including campaigns linked to ransomware operators and state-sponsored groups. In addition, Shadowserver tracks nearly 6,000 internet-exposed ScreenConnect instances, increasing the potential for opportunistic exploitation if file-transfer permissions remain enabled.

What is the exposure or risk?

Organizations face exposure when ScreenConnect technician roles retain file-transfer permissions for Support and Access sessions. Threat actors could potentially leverage these permissions to move malicious or sensitive files during remote sessions.

Until ConnectWise releases a permanent fix, organizations face increased risk of unauthorized file movement and follow-on compromise activity across managed environments. The risk is particularly high in environments where technician accounts have broad privileges.

What are the recommendations?

Barracuda recommends the following actions to reduce risk:

  • Implement ConnectWise’s interim mitigation immediately: Remove the TransferFiles permission, or TransferFilesInSession for legacy roles, from relevant session groups under Administration > Security > Roles. Apply the changes across all applicable roles.
  • Review all ScreenConnect deployments: Verify both cloud-hosted and on-premises instances. Identify and remediate technician roles that retain file-transfer permissions.
  • Monitor for suspicious file-transfer activity: Review ScreenConnect administrative actions and investigate recent Support and Access session file transfers for unusual behavior, especially in highly privileged environments.
  • Prepare to deploy the permanent fix: Monitor the ConnectWise advisory for updated guidance, CVE details, and patched releases as they become available.
  • Minimize operational disruption: Identify technician workflows that depend on transferring tools, scripts, logs, or packages. Establish approved alternatives until ConnectWise releases and validates a permanent fix.

References

For more in-depth information about the recommendations, please visit the following links:

If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.


Share This:
Asaad Shaikh

Posted by Asaad Shaikh

Asaad is a Cybersecurity Analyst at Barracuda. He supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.