An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-7191 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:17:40.108Z

Reserved: 2019-09-19T00:00:00

Link: CVE-2019-16514

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-23T18:15:13.523

Modified: 2024-11-21T04:30:44.333

Link: CVE-2019-16514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.