Unauthenticated RCE exploit module for ConnectWise ScreenConnect (CVE-2024-1709) by sfewer-r7 · Pull Request #18870 · rapid7/metasploit-framework (original) (raw)

@sfewer-r7

@sfewer-r7 changed the titlefix tabs Unauthenticated RCE exploit module for ConnectWise ScreenConnect (No CVE at this time)

Feb 21, 2024

@sfewer-r7

adfoster-r7

adfoster-r7

adfoster-r7

adfoster-r7

adfoster-r7

@sfewer-r7

@sfewer-r7

@sfewer-r7 sfewer-r7 changed the titleUnauthenticated RCE exploit module for ConnectWise ScreenConnect (No CVE at this time) Unauthenticated RCE exploit module for ConnectWise ScreenConnect (CVE-2024-1709)

Feb 21, 2024

@sfewer-r7

@sfewer-r7

… we dont drop the Metasploit payload to disk.

@sfewer-r7

…and not accidentaly copy the full stop charachter)

@sfewer-r7

…leverage the path traversal CVE-2023-1708 to ensure the dropped ASHX file can be reached. This was blocking the Linux target from working. Also works fine on Windows. We leverage FileDropper mixin to delete this file.

@sfewer-r7

@sfewer-r7

@sfewer-r7

… we try to inject an x86 payload in-memory we crash the target x64 service.

@sfewer-r7

… the version number (we can determine this with a single request, so there is no major change here). This is usefull so you know what platform to set the exploits target to (so you can select an appropriate payload). Thanks @iagox86 for the idea!

jheysel-r7

@sfewer-r7

…default to a random value. Also use Faker::Internet.email to gen an email address

@sfewer-r7

@sfewer-r7

@sfewer-r7

…ded a second link, so adding that to the docs

canders-crwd

@sfewer-r7 sfewer-r7 deleted the connectwise-screenconnect-rce branch

July 4, 2024 08:59

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})