📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

ScreenConnect Client ScreenConnect Software

ScreenConnect Client 25.6.5.9377

Latest tracked version 25.6.5.9377. Release status, tracked CVEs, and automated cross-platform patching for ScreenConnect Client.

PlatformLatest versionCVEs trackedLast checked
Windows25.6.5.937782024-05-23

Known vulnerabilities (CVEs) in ScreenConnect Client

Lavawall tracks 8 published CVEs affecting ScreenConnect Client, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2025-39352025-04-25 19:15:49HIGH (8)ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server.  The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior.  This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.NETWORK
CVE-2025-148232025-12-18 16:15:53MEDIUM (5)In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an encrypted representation could be exposed in client responses. Updating the Certificate Signing Extension to version 1.0.12 or higher ensures configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.NETWORK
CVE-2025-142652025-12-11 15:15:47CRITICAL (9)In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.NETWORK
CVE-2024-17092024-02-21 16:15:50CRITICAL (10)ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems. NETWORK
CVE-2024-17082024-02-21 16:15:50HIGH (8)ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. NETWORK
CVE-2023-472572024-02-01 22:15:55HIGH (8)ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.NETWORK
CVE-2023-472562024-02-01 22:15:55MEDIUM (6)ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settingsLOCAL
CVE-2022-367812022-09-28 20:15:12MEDIUM (5)ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks. NETWORK

Why keeping ScreenConnect Client patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every ScreenConnect Client release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches ScreenConnect Client

Lavawall® watches ScreenConnect Client releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on ScreenConnect Client, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of ScreenConnect Client?
Lavawall tracks ScreenConnect Client at version 25.6.5.9377 (last checked 2024-05-23). New releases are monitored continuously and can be deployed automatically across your fleet.
Does ScreenConnect Client have known security vulnerabilities (CVEs)?
Lavawall tracks 8 CVEs for ScreenConnect Client and remediates them automatically as part of patching.
How do I patch ScreenConnect Client automatically?
Deploy the Lavawall® agent and ScreenConnect Client updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for ScreenConnect Client through public information and proprietary statistical analysis, and can patch it automatically across your fleet.