A security flaw affecting file transfers in ScreenConnect is being linked to malware campaigns that can spread malicious scripts across connected systems. ConnectWise has confirmed the issue affects both cloud-hosted and on-premises deployments of its ScreenConnect Remote Support and Access software, raising concerns for IT departments and managed service providers that rely on the platform.
ConnectWise Confirms ScreenConnect File Transfer Flaw
ConnectWise acknowledged the vulnerability in a September 3 security advisory and said a formal vulnerability identifier and patch were being prepared.
“A CVE identifier and an official fix will be issued within the week,” the company wrote.
ScreenConnect is widely used for remote technical support and system administration. Organizations can use ConnectWise-hosted cloud deployments or operate ScreenConnect themselves on-premises or within private cloud environments.
Because remote monitoring and management tools can provide extensive access to corporate systems, vulnerabilities or compromised deployments can create significant security risks for organizations, including Canadian businesses that rely on managed IT services.
Rogue ScreenConnect Clients Used to Spread Malware
The ConnectWise advisory followed research from cybersecurity company Huntress, which documented attacks involving rogue ScreenConnect clients capable of distributing malware to newly connected machines.
According to Huntress, the incidents began with social engineering that resulted in malicious ScreenConnect instances being installed on victims’ computers.
The researchers said this method was consistent with broader cybercrime trends, noting that “RMM abuse is a top attack vector” the company has tracked over the past year.
Attackers Deploy Multiple VBScript Files
After installation, the rogue ScreenConnect clients repeatedly launched Windows Script Host processes. Huntress identified this as unusual behaviour and found that the activity was being used to deploy four VBScript files named 1.vbs through 4.vbs.
Attackers were also observed creating a Windows registry Run Key called WindowsServiceHost. The key pointed to a corresponding script stored in the affected user’s AppData directory, providing a mechanism that could help maintain persistence.
“An analysis of the payloads used in the attack revealed a staged attack designed to profile hosts and conceal activity. Perhaps the most interesting part of the attack chain was that it used modified ScreenConnect clients to propagate the VBScript chain (specifically executing the four files (1.vbs to 4.vbs) to connected ScreenConnect endpoints, creating worm-like spread across newly connected systems,” the researchers noted.
The scripts performed system discovery and retrieved or launched additional components.
Huntress identified payloads associated with persistence mechanisms, additional ScreenConnect installations, network tunnelling, changes to security controls and cryptocurrency mining.
ConnectWise Recommends Disabling File Transfers
Until an official ScreenConnect security update is available, ConnectWise is recommending that partners disable technician file-transfer capabilities.
Administrators can make the change by navigating to Administration > Security > Roles and editing every assigned role. Permissions should then be reviewed for each applicable session group.
If TransferFiles, or TransferFilesInSession on older versions, is enabled, administrators should deselect the permission. The change needs to be applied individually to every relevant role.
“This setting change does not require a version upgrade and can be applied immediately,” ConnectWise stated.
The temporary measure is intended to reduce exposure while organizations wait for the official fix.
Organizations Urged to Review ScreenConnect Logs
Huntress is also advising administrators to examine ScreenConnect audit logs for suspicious RunFiles or RanFiles entries associated with a guest process.
Systems already displaying evidence of compromise should receive more extensive remediation. Huntress recommends reimaging affected machines using known-good media rather than relying solely on removing individual malicious files.
The company also urged organizations operating their own ScreenConnect infrastructure to pay particular attention to those deployments.
“From our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,” Huntress added.
ScreenConnect Security Issue Highlights RMM Risks
The incident underscores the security challenges surrounding remote monitoring and management software. These tools are essential for many IT teams and MSPs, but their privileged access can also make compromised installations valuable to attackers.
Organizations using ScreenConnect should review file-transfer permissions, inspect audit logs for suspicious activity and apply the official ConnectWise security update once it becomes available. Until then, restricting file transfers provides an immediate step to reduce the risk of malware spreading through affected ScreenConnect environments.

William Faulkner was a Nobel Prize-winning American novelist and short story writer renowned for his innovative literary techniques and profound exploration of the American South. His works remain among the most influential contributions to twentieth-century literature.
