9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.
AI Analysis
Improper server-side validation in the ScreenConnect extension framework allows for the execution of untrusted or arbitrary extensions, potentially leading to custom code execution or unauthorized access to application configuration data.
Basic Information
ID
CVE-2025-14265
Source
ConnectWise
Published
Dec 11, 2025 at 14:21
Modified
Dec 11, 2025 at 14:43
Affected Product
Vendor
ConnectWise
Product
ScreenConnect
Version
All versions prior to 2025.8
Affected Versions
ConnectWise ScreenConnect All versions prior to 2025.8
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
ConnectWise
Product
ScreenConnect
Version
All versions prior to 25.8