An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-23T17:21:38

Updated: 2024-08-05T01:17:40.108Z

Reserved: 2019-09-19T00:00:00

Link: CVE-2019-16514

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-01-23T18:15:13.523

Modified: 2020-01-28T14:42:29.977

Link: CVE-2019-16514

cve-icon Redhat

No data.