ConnectWise ScreenConnect Path Traversal (CVE-2024-1708) Added to CISA KEV — Storm-1175 / Medusa Ransomware Active Exploitation — Threadlinqs Intelligence
As of 2026-05-30, ConnectWise ScreenConnect Path Traversal (CVE-2024-1708) Added to CISA KEV — Storm-1175 / Medusa Ransomware Active Exploitation is a high-severity vulnerability threat attributed to Storm-1175 (CN), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0436 · Severity: HIGH · CVSS: 8.4 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Storm-1175 · CN
On April 28, 2026, CISA added CVE-2024-1708, a ConnectWise ScreenConnect path traversal vulnerability (CWE-22, CVSS 8.4), to the Known Exploited Vulnerabilities catalog with an FCEB remediation
CVE-2024-1708 is a path traversal vulnerability (CWE-22) in the ConnectWise ScreenConnect web management interface that affects all on-premises versions 23.9.7 and earlier. The flaw resides in how the application validates and constructs file paths when handling extension uploads via the App_Extensions subsystem. By submitting attacker-controlled path segments containing parent-directory references, an authenticated administrator (or an attacker who has obtained admin via the paired bypass) can write arbitrary files outside the intended extensions directory and into web-accessible locations under the ScreenConnect installation tree. When combined with the ability to upload .aspx content, this primitive yields reliable unauthenticated remote code execution under the ScreenConnect service account, which on Windows installations runs with elevated privileges.
In observed in-the-wild operations, CVE-2024-1708 is invariably chained with CVE-2024-1709, an authentication bypass (CWE-288, CVSS 10.0) in the SetupWizard component. CVE-2024-1709 stems from missing access control on the /SetupWizard.aspx endpoint when accessed via a path that includes a trailing path segment (for example /SetupWizard.aspx/anything). On a fully-installed instance this endpoint should reject access, but the routing logic strips or fails to authenticate the supplemental path, returning the initial setup form to anonymous callers. The attacker walks the wizard, creates a brand new local administrator on the ScreenConnect tenant, authenticates with that account, and then leverages the path-traversal primitive in CVE-2024-1708 to drop a web shell or extension that yields code execution. The composite result is full unauthenticated takeover of the ScreenConnect server and any endpoint enrolled into it — every managed device becomes reachable for command execution, file transfer and on-demand remote access.
ConnectWise was notified of both flaws by researchers at Outpost24 (Mick Behrens) on February 13, 2024 and released ScreenConnect 23.9.8 on February 19, 2024 to remediate the chain on the on-premises product line; cloud tenants on screenconnect.com and hostedrmm.com were patched directly by ConnectWise. Within hours of disclosure, Huntress published full technical analysis with screenshots and a working proof-of-concept, and within 48 hours mass exploitation by multiple ransomware affiliates was reported, including Black Basta, BlackCat/ALPHV, LockBit and Cl0p clusters. CVE-2024-1709 was added to the CISA KEV catalog on February 22, 2024.
In April 2026, Microsoft Threat Intelligence published a detailed campaign report titled 'Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations'. Microsoft assesses with high confidence that Storm-1175, a financially motivated actor and prolific Medusa Ransomware-as-a-Service affiliate, has industrialized the CVE-2024-1708/1709 chain alongside other web-facing exposures (Fortinet FortiOS, GeoServer, JetBrains TeamCity) as primary entry points. Following exploitation of ScreenConnect, Storm-1175 deploys legitimate remote management tooling — most commonly Mesh Agent, SimpleHelp, and AnyDesk — for redundant persistence, then performs Active Directory reconnaissance, credential dumping via comsvcs.dll-based LSASS dumps, lateral movement using harvested credentials and RDP, and finally double-extortion deployment of Medusa ransomware. Data exfiltration is staged via Rclone to attacker-controlled cloud buckets, with BITSAdmin frequently used to stage tooling. Microsoft observed intrusions impacting healthcare, education, professional services and finance verticals across Australia, the United Kingdom and the United States, with leak-site listings consistent with the campaign timeline.
CISA added CVE-2024-1708 to the KEV catalog on April 28, 2026 — more than two years after disclosure — citing direct evidence of active exploitation surfaced by Microsoft and incident response partners
Target sectors: healthcare, education, professional-services, finance, managed-service-providers
Target regions: Australia, United Kingdom, United States
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2024-1708, CVE-2024-1709, T1190, T1133, T1059, T1059, T1505, T1136, T1543, T1078, T1562, T1070