CVE-2024-1708, a path traversal vulnerability in ConnectWise ScreenConnect versions 23.9.7 and earlier, carries a CVSS score of 8.4 and is flagged in CISA's KEV catalogue with a designation that most entries in this series don't carry: known ransomware campaign use.
Why one remote-access tool vulnerability outranks most standalone CVEs
ScreenConnect is remote monitoring and management (RMM) software — the category of tool that IT service providers and managed service providers (MSPs) install to remotely access and administer client systems. NVD's description is characteristically terse: "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems." The CVSS vector reflects a scope-changed (S:C) attack requiring some user interaction (UI:R) but delivering complete confidentiality, integrity, and availability impact once triggered — consistent with a vulnerability chained alongside the related authentication-bypass issue disclosed at the same time, which Huntress's referenced research bluntly titled "A Catastrophe for Control: Understanding the ScreenConnect Authentication Bypass."
That framing wasn't hyperbole. RMM software occupies a uniquely privileged position in the security stack of any organization that uses it: it exists specifically to grant a technician full administrative access to a remote endpoint, which means compromising the RMM platform itself doesn't just compromise one system — it hands an attacker the same privileged remote-access channel the legitimate operator uses, potentially across every client system that instance manages. This is precisely why CISA's KEV entry for this CVE notes known ransomware campaign use: Microsoft's own referenced security blog, published in April 2026, is titled "Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations" — directly tying exploitation of vulnerable, internet-facing ScreenConnect instances to an active, named ransomware operation.
The mechanics: path traversal as a stepping stone, not the whole story
Path traversal vulnerabilities are, in isolation, often considered a lower-tier finding — they let an attacker read or write files outside an intended directory, which sounds contained until you consider what "write files outside an intended directory" means inside a remote administration product. In ScreenConnect's case, the path traversal flaw combined with the concurrently disclosed authentication bypass to form a chain: gain unauthenticated access to setup functionality, then use path traversal to reach and manipulate files that shouldn't be reachable, ultimately enabling remote code execution on the ScreenConnect server itself. That server, by design, has trusted, standing remote-access relationships with every endpoint it manages — which is exactly the kind of "keys to the kingdom" position that turns a single web-application vulnerability into an MSP-wide, multi-client incident.
Why MSP software specifically deserves elevated scrutiny
The core lesson from CVE-2024-1708's exploitation history isn't really about path traversal as a bug class — it's about what category of software this bug lived in. Any tool built to provide privileged, centralized remote access to many downstream systems inherits a form of systemic risk that ordinary business applications don't carry: a single compromised instance doesn't stay contained to the server it runs on. It cascades outward to every system that trusts it, precisely because trust and reach are the entire value proposition of RMM software. That's the same underlying logic driving ransomware operators like Storm-1175 to specifically target vulnerable, internet-facing instances of these platforms rather than going after individual endpoints one at a time — compromising the RMM layer is a force multiplier that individual endpoint compromise simply cannot match.
What to check this week
Confirm ScreenConnect is patched to 23.9.8 or later across every instance, including any that may be run by a downstream MSP on your organization's behalf rather than by internal IT directly.
Ask any MSP or third-party IT provider directly whether their ScreenConnect deployment has been patched, since this vulnerability's ransomware association means the exposure isn't limited to organizations running the software themselves — it extends to every client of an unpatched provider.
Review ScreenConnect server logs for the specific timeframe this vulnerability was actively exploited, looking for anomalous setup-page access or file operations outside expected directories, given the confirmed ransomware campaign use.
Restrict network exposure of any internet-facing ScreenConnect instance to the minimum required, since Microsoft's referenced research specifically calls out "vulnerable web-facing assets" as the entry point Storm-1175 targeted.
A closing note on the disclosure-to-exploitation timeline
CVE-2024-1708 was disclosed in February 2024, yet its associated ransomware campaign activity — per the Microsoft blog referenced in this KEV entry — was still being reported in April 2026, over two years later. That gap underscores a recurring theme across this series: a two-year-old, publicly known vulnerability in privileged remote-access software remained a live ransomware entry point long after the fix was available, which speaks less to the difficulty of patching and more to how many vulnerable instances simply never got the update.
A final consideration on supply-chain-style risk in the MSP model
Any organization that outsources IT operations to a managed service provider inherits that provider's security posture on tools like ScreenConnect as if it were their own — a fact worth raising directly in vendor risk conversations rather than assuming it's covered by the existing contract.
How Safeguard helps
Safeguard's continuous inventory tracks remote-access and RMM software with the elevated priority this category demands, recognizing that a single vulnerable instance of a platform built for privileged, centralized access carries risk that extends far beyond the server it runs on.