CVE-2025-14265
Improper server-side validation in ScreenConnect extension framework
Description
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.
INFO
Published Date :
Dec. 11, 2025, 3:15 p.m.
Last Modified :
Dec. 12, 2025, 3:18 p.m.
Remotely Exploit :
Yes !
Source :
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | 7d616e1a-3288-43b1-a0dd-0a65d3e70a49 |
Solution
- Upgrade ScreenConnect to version 25.8.
- Verify extension subsystem integrity checks.
- Restrict installation to trusted extensions.
- Apply all available security updates.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-14265.
| URL | Resource |
|---|---|
| https://www.connectwise.com/company/trust/security-bulletins/screenconnect-2025.8-security-patch |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-14265 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-14265
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-14265 vulnerability anywhere in the article.
-
CybersecurityNews
Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more
In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped ... Read more
-
CybersecurityNews
Critical ScreenConnect Vulnerability Let Attackers Expose Sensitive Configuration Data
ConnectWise has issued a security update for ScreenConnect™ to address a critical vulnerability that could enable attackers to expose sensitive configuration data and install untrusted extensions. The ... Read more
-
Daily CyberSecurity
Critical OpenShift GitOps Flaw Risks Cluster Takeover (CVE-2025-13888) via Privilege Escalation to Root
A critical vulnerability has been uncovered in Red Hat OpenShift GitOps, exposing Kubernetes clusters to a complete takeover by users with limited privileges. Tracked as CVE-2025-13888 with a severity ... Read more
-
Daily CyberSecurity
Critical ScreenConnect Flaw (CVE-2025-14265) Risks Config Exposure & Untrusted Extension Installation
ConnectWise has issued an important security update for its widely used remote support software, ScreenConnect, addressing a critical vulnerability that could expose sensitive configuration data. The ... Read more
-
Daily CyberSecurity
Enterprise Alert: Windows 10 Update KB5071546 Breaks MSMQ Service with Insufficient Permissions
Microsoft has recently published documentation confirming that installing the extended security update KB5071546 on Windows 10 can cause failures in Microsoft Message Queuing (MSMQ). MSMQ is a service ... Read more
The following table lists the changes that have been made to the
CVE-2025-14265 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
Dec. 11, 2025
Action Type Old Value New Value Added Description In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed. Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Added CWE CWE-494 Added Reference https://www.connectwise.com/company/trust/security-bulletins/screenconnect-2025.8-security-patch