Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 24 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers

by The Gurus
January 11, 2024
in News, Uncategorized
Critical Security Vulnerabilities Identified in ConnectWise ScreenConnect by Gotham Security Researchers
Share on FacebookShare on Twitter

Gotham Security, an Abacus Group company providing high-quality boutique cybersecurity services, has announced that its research team recently discovered two vulnerabilities in ConnectWise ScreenConnect, saving tens of thousands of enterprises from the possible consequences of a significant cyber-attack.

ConnectWise ScreenConnect is a remote-control software used by IT managed service providers (MSPs) globally. Had Gotham Security not stepped in, therefore, and had a hacker identified the vulnerabilities as part of a zero-day attack, it would likely have led to MSPs and their clients being exposed to this zero-day vulnerability.

If the vulnerabilities were left unaddressed, bad actors would have been able to gain access to all workstations and servers with ScreenConnect from a local network and then escalate their privileges to be local administrators on the affected systems.

Gotham Security acted quickly to mitigate this possibility, rapidly developing a technical write-up about the vulnerabilities and disclosing it to ConnectWise in accordance with its Vulnerability Disclosure Policy. Within an hour of submission, ConnectWise had triaged the vulnerabilities and assigned security engineers to replicate Gotham Security’s findings. Later that same day, both findings were confirmed as valid. ConnectWise then initiated the development of a security patch to address both vulnerabilities.

Christian Scott, Chief Operating Officer and Chief Information Security Officer Gotham Security, said: “Our success in identifying and disclosing these vulnerabilities so quickly is testament to the hard work and dedication of our team and just one more example of how our technical know and cyber-security research helps protect organisations worldwide.”

Scott added, “This incident shows the benefits of a partnership-based approach. ConnectWise were fast to engage and did a great job in responding to these vulnerabilities and pushing out a patch to rectify them as quickly as possible.”

Paul Ponzeka, Chief Technology Officer, Abacus Group, said: “Abacus Group recognises the exceptional technical prowess of Gotham in the realm of security. Gotham has demonstrated a unique capability in uncovering vulnerabilities at a speed that other boutique providers would struggle to match.

 

“Our experience with Gotham goes beyond the superficial ‘paper security’ offered by others. Christian and his team have not only identified but also actively engaged in resolving software vulnerabilities, working directly with vendors. This hands-on approach and direct problem-solving attitude sets Gotham apart in the field of cybersecurity.

 

“It also underlines the value of a tight coupling between an MSP like ourselves and a cybersecurity company like Gotham Security,” Ponzeka added. “Gotham Security’s close relationship with us allowed them to quickly develop and implement mitigation strategies to protect all of our customers while ConnectWise worked on developing a patch.”

 

For more details of the ScreenConnect vulnerability and how it was addressed, please visit Discovering ConnectWise ScreenConnect RCE & LPE Vulnerabilities (CVE-2023-47256, CVE-2023-47257) (gotham-security.com)

ShareTweet
Previous Post

Keeper Security Unveils Granular Sharing Enforcements for Easier Compliance

Next Post

Bitcoin ETFs Approved Following Official SEC X Account Compromise

Recent News

Security Training Needs Google Maps, Not Christopher Columbus

Security Training Needs Google Maps, Not Christopher Columbus

June 24, 2026
Quantum computing: The data security conundrum

Trump Sets Post-Quantum Security Deadlines as White House Warns of Advanced Cryptographic Threats

June 23, 2026

Experts Warn: Passwords Still Winning Despite Passwordless Push

June 23, 2026
How Do Online Gaming Sites Keep Players and Their Data Safe?

KnowBe4 awarded in the email security industry

June 23, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol