La vulnerabilità di cryptographic signature verification può esporre gli ASP.NET machine keys e permettere autenticazione di sessioni non autorizzate e escalation di privilegi. Elastic Security Labs ha osservato il loader SILENTCONNECT che, tramite VBScript multistage e in-memory PowerShell, distribuisce ScreenConnect e abilita hands-on access su host compromessi.
Part of the PlainSec briefing for 2026-03-20
Every edition of this story: ScreenConnect vulnerabile, SILENTCONNECT abilita accesso non autorizzato