CVE-2019-16514 describes a critical remote code execution vulnerability in ConnectWise Control (formerly ScreenConnect) version 19.3.25270.7185. The flaw allows authenticated administrative users to upload a malicious unsigned extension ZIP file containing executable code, which the server then executes. Rated with a CVSS score of 7.2 (High), this vulnerability poses a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence or active exploitation has been observed, and community discussion is minimal, the high EPSS score indicates a non-negligible probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.3.25270.7185CPE matchmatch criteria | cpe:2.3:a:connectwise:control:19.3.25270.7185:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.