ConnectWise、ScreenConnectの重大な認証不備を5日後に修正

新たな脆弱性の公表を受け、同社はユーザーの不安払拭に努めています

ConnectWiseは、ScreenConnectのセキュリティアップデートを公開しました。これは、アクティブなリモートセッションを通じて、認可も確認もなしにファイルの転送・実行が可能になってしまう問題があると同社が顧客に警告してから、5日後のことです。

同社は9月3日に顧客へ警告し、ConnectWise Remote Accessのサポート・アクセスセッションに問題があることを明らかにしました。あわせて、開いているセッションを持つユーザーについては管理者がログインし、「TransferFiles」権限を削除するよう呼びかけていました。

この脆弱性はCVE-2026-84869として追跡されており、ScreenConnectクライアントのバージョン26.6.5以降で修正済みです。

Maxwell began writing about technology in 1984, when mainframes ruled the world. Since then he has written for just about every business computing title in the UK, and for a few in the US, covering everything from Artificial intelligence to Zero-day exploits and all points in between. He has also been editor-in-chief of several award-winning titles, including Network Week, Techworld, and Cloud Pro, and a regular contributor to Whatsonstage.com. In his spare time he coaches a junior rugby team.

翻訳元: https://www.csoonline.com/article/4221263/connectwise-patches-critical-screenconnect-authentication-failure-after-five-days-2.html

本記事は csoonline.com の記事を翻訳・要約したものです。