ScreenConnect vulnerabile, SILENTCONNECT abilita accesso non autorizzato

La vulnerabilità di cryptographic signature verification può esporre gli ASP.NET machine keys e permettere autenticazione di sessioni non autorizzate e escalation di privilegi. Elastic Security Labs ha osservato il loader SILENTCONNECT che, tramite VBScript multistage e in-memory PowerShell, distribuisce ScreenConnect e abilita hands-on access su host compromessi.

Part of the PlainSec briefing for 2026-03-20

Every edition of this story: ScreenConnect vulnerabile, SILENTCONNECT abilita accesso non autorizzato

Sources