Critical ScreenConnect flaw lets an admin run arbitrary code
CVE-2025-14265 is a critical CVSS 9.1 vulnerability in ConnectWise ScreenConnect affecting server versions prior to 25.8. It stems from inadequate server-side validation and integrity checks in the extension subsystem, letting an authorised or administrative user install and execute untrusted extensions. That can lead to arbitrary code execution and access to configuration data. Only the server component is affected, not host or guest clients. ConnectWise has released version 25.8; cloud-hosted instances update automatically, while on-premises installations must be upgraded manually. The vendor rates the issue as important with moderate priority, and no exploitation in the wild has been confirmed.
What this means for your organisation
Remote management tooling is one of the most valuable footholds an attacker can gain, because it reaches many machines at once. Requiring admin access lowers the likelihood but does not remove it: a hijacked admin account or a managed service provider with overly broad rights is a realistic route in. For organisations whose remote support is delivered by an IT partner, this is as much a supplier question as an operational one.
Berigo recommends
- Upgrade self-hosted ScreenConnect servers to 25.8, and ask your IT provider to confirm in writing that their instance is patched.
- Reduce the number of admin accounts in the tool and require phishing-resistant MFA on those that remain.
- Put the management interface behind access control so it is not open to the internet.
- Enable alerting when new extensions are installed, and review the ones already present.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch