Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14265

Опубликовано: 11 дек. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*
Версия до 25.8.0.9438 (исключая)

EPSS

Процентиль: 16%
0.00052
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.1
github
около 2 месяцев назад

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.

EPSS

Процентиль: 16%
0.00052
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-494