CVE-2025-3935 is a critical ViewState code injection vulnerability affecting ConnectWise ScreenConnect versions 25.2.3 and earlier, stemming from platform-level behavior rather than a ScreenConnect flaw. This high-severity vulnerability (CVSS 7.2) allows authenticated attackers with compromised machine keys to achieve remote code execution by sending a malicious ViewState. It is actively exploited in the wild, as indicated by its inclusion in CISA's KEV catalog and significant media coverage, despite a lack of public exploit code. ScreenConnect 2025.4 resolves this by disabling ViewState.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.2.4CPE matchmatch criteria | cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.