Full Report
Our team has been tracking conversations surrounding ConnectWise Control vulnerabilities and alleged exploitation. We politely disagree with the threat and criticality presented by the security researcher.
Analysis Summary
# Vulnerability: ConnectWise Control URL Parameter Validation (Social Engineering Flaw)
## CVE Details
* **CVE ID:** N/A (The vendor and Huntress dispute the initial "Critical RCE" claims; no CVE for RCE was assigned based on this specific report).
* **CVSS Score:** N/A (Categorized by Huntress as a low-risk social engineering concern rather than a functional software vulnerability).
* **CWE:** CWE-79 (Improper Neutralization of Input During Web Page Generation / Potential for Reflected Content) or general "Social Engineering" weakness.
## Affected Systems
* **Products:** ConnectWise Control (formerly ScreenConnect)
* **Versions:** All versions prior to 22.8.10013
* **Configurations:** Self-hosted and Cloud instances where installers are generated via URL parameters.
## Vulnerability Description
The issue involves a lack of strict validation for client installer URL parameters. While initially reported by an external researcher as a Remote Code Execution (RCE) flaw, technical analysis by Huntress and ConnectWise determined it was actually a weakness that allowed attackers to manipulate the visible metadata or filenames of generated installers. This could be used in phishing campaigns to make a malicious or legitimate-but-repurposed remote access tool appear more trustworthy to an end-user during a social engineering attack.
## Exploitation
* **Status:** Not exploited as a functional RCE; however, the mechanism (using ConnectWise Control in phishing) is **exploited in the wild**.
* **Complexity:** Low (Requires only URL manipulation).
* **Attack Vector:** Network (Phishing/Social Engineering).
## Impact
* **Confidentiality:** Low (No direct data exposure through the flaw itself).
* **Integrity:** Low (Does not allow unauthorized modification of system data, only cosmetic installer naming).
* **Availability:** None.
* **Note:** The primary impact is the erosion of trust, as attackers use the legitimate tool to gain remote access via user consent.
## Remediation
### Patches
* **ConnectWise Control version 22.8.10013:** This stable release includes additional validation of client installer URL parameters to inhibit social engineering attacks.
### Workarounds
* **User Training:** Educate users and administrators to only download installers from verified, internal sources.
* **Restricted Access:** Limit the ability of unauthorized users to access the Control host page where installers are generated.
## Detection
* **Indicators of Compromise:**
* Unexpected installer files with suspicious names (e.g., "GeekSquad_Support.exe" or "Amazon_Refund.msi") originating from your ConnectWise instance.
* URL strings containing unusual or excessive encoded parameters in the `/files/` directory of the Control server.
* **Detection Methods:** Monitor web server logs for atypical URL parameters being passed to the installer generation engine.
## References
* ConnectWise Control 22.8 Release Notes: hxxps[://]control[.]product[.]connectwise[.]com/communities/26/topics/4135-connectwise-control-228
* Huntress Analysis: hxxps[://]www[.]huntress[.]com/blog/clearing-the-air-overblown-claims-of-vulnerabilities-exploits-severity
* Silent Push Phishing Advisory: hxxps[://]www[.]silentpush[.]com/blog/silent-push-uncovers-a-large-phishing-operation-featuring-amazon-geek-squad-mcafee-microsoft-norton-and-paypal-domains