DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2025-3935

High CISA KEV
Low Medium High Critical
8.1
CVSS Score
Published: Apr 25, 2025
Last Modified: Oct 24, 2025

Vulnerability Description

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. 
It is important to note that to obtain these machine keys, privileged system level access must be obtained.



If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. 



The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior.  This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

21 configuration(s) from 1 vendor(s)

screenconnect
Version:
25.1.10
CPE:
cpe:2.3:a:connectwise:screenconnect:25.1.10:*:*:*:*:*:*:*
screenconnect
Version:
25.1.8
CPE:
cpe:2.3:a:connectwise:screenconnect:25.1.8:*:*:*:*:*:*:*
screenconnect
Version:
23.8.4
CPE:
cpe:2.3:a:connectwise:screenconnect:23.8.4:*:*:*:*:*:*:*
screenconnect
Version:
25.2.3
CPE:
cpe:2.3:a:connectwise:screenconnect:25.2.3:*:*:*:*:*:*:*
screenconnect
Version:
25.1.9
CPE:
cpe:2.3:a:connectwise:screenconnect:25.1.9:*:*:*:*:*:*:*
screenconnect
Version:
24.4.6
CPE:
cpe:2.3:a:connectwise:screenconnect:24.4.6:*:*:*:*:*:*:*
screenconnect
Version:
24.4.0
CPE:
cpe:2.3:a:connectwise:screenconnect:24.4.0:*:*:*:*:*:*:*
screenconnect
Version:
24.3.7
CPE:
cpe:2.3:a:connectwise:screenconnect:24.3.7:*:*:*:*:*:*:*
screenconnect
Version:
23.9.8
CPE:
cpe:2.3:a:connectwise:screenconnect:23.9.8:*:*:*:*:*:*:*
screenconnect
Version:
24.3.5
CPE:
cpe:2.3:a:connectwise:screenconnect:24.3.5:*:*:*:*:*:*:*
screenconnect
Version:
24.4.1
CPE:
cpe:2.3:a:connectwise:screenconnect:24.4.1:*:*:*:*:*:*:*
screenconnect
Version:
22.7
CPE:
cpe:2.3:a:connectwise:screenconnect:22.7:*:*:*:*:*:*:*
screenconnect
Version:
24.3.6
CPE:
cpe:2.3:a:connectwise:screenconnect:24.3.6:*:*:*:*:*:*:*
screenconnect
Version:
25.1.5
CPE:
cpe:2.3:a:connectwise:screenconnect:25.1.5:*:*:*:*:*:*:*
screenconnect
Version:
25.1.4
CPE:
cpe:2.3:a:connectwise:screenconnect:25.1.4:*:*:*:*:*:*:*
screenconnect
Version:
24.4.2
CPE:
cpe:2.3:a:connectwise:screenconnect:24.4.2:*:*:*:*:*:*:*
screenconnect
Version:
24.4.4
CPE:
cpe:2.3:a:connectwise:screenconnect:24.4.4:*:*:*:*:*:*:*
screenconnect
Version:
24.3.4
CPE:
cpe:2.3:a:connectwise:screenconnect:24.3.4:*:*:*:*:*:*:*
screenconnect
Version:
24.4.5
CPE:
cpe:2.3:a:connectwise:screenconnect:24.4.5:*:*:*:*:*:*:*
screenconnect
Version:
25.1.7
CPE:
cpe:2.3:a:connectwise:screenconnect:25.1.7:*:*:*:*:*:*:*
screenconnect
Version:
23.8.5
CPE:
cpe:2.3:a:connectwise:screenconnect:23.8.5:*:*:*:*:*:*:*
This vulnerability affects 21 software configuration(s). Ensure you patch all affected systems.

Severity Details

8.1
out of 10.0
High

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Key Information

Published Date
April 25, 2025