ConnectWise to Update ScreenConnect Code Signing Certificates for Enhanced Security

Published:

spot_img

ConnectWise Takes Proactive Measures to Address Security Concerns

Date: June 12, 2025
Author: Ravie Lakshmanan
Tags: Vulnerability, Software Security


ConnectWise recently announced plans to rotate the digital code signing certificates for several of its key products, including ScreenConnect, ConnectWise Automate, and ConnectWise remote monitoring and management (RMM) executables. This decision is driven by security issues identified by a third-party researcher concerning how ScreenConnect managed certain configuration data in earlier versions.

The Security Concern

While ConnectWise has not disclosed the specifics publicly, additional details surfaced in a private FAQ shared with customers and later discussed on platforms like Reddit. The primary issue involves ScreenConnect’s method of storing configuration data within an installer section that is not signed, though it remains a part of the installer package. This area is utilized to convey essential configuration data for connection setups, such as the URL where the agent should make callbacks. While the approach aims to maintain the digital signature’s validity, it raises concerns about creating an insecure design pattern under today’s security standards.

Planned Updates and Enhancements

In conjunction with the certificate rotation, ConnectWise is implementing an update intended to enhance the management of configuration data within ScreenConnect. This dual-action approach demonstrates the company’s commitment to addressing potential vulnerabilities proactively.

The revocation of the existing digital certificates is scheduled for June 13 at 8 p.m. ET (June 14, 12 a.m. UTC). Importantly, ConnectWise has clarified that this situation does not stem from any sort of compromise affecting their systems or certificates.

Automatic Updates and User Responsibilities

ConnectWise noted that it has already begun updating certificates and agents across all cloud instances of Automate and RMM. However, users operating on-premise versions of ScreenConnect or Automate must take initiative. These customers are urged to update to the latest build and confirm that all their agents are current before the specified cutoff to prevent service disruption.

ConnectWise reassured users by stating, "We had already planned enhancements to certificate management and product hardening, but these efforts are now being implemented on an accelerated timeline." The company recognizes that transitioning may present challenges and has committed to supporting its users throughout the process.

Recent Security Threats and Response

This security announcement follows closely on the heels of another significant concern: a suspected nation-state actor allegedly breaching ConnectWise’s systems and affecting a small user group by exploiting vulnerabilities (specifically CVE-2025-3935) for ViewState code injection attacks.

As cybercriminals increasingly leverage legitimate RMM software like ScreenConnect to gain covert, persistent remote access, the landscape of cybersecurity threats is evolving rapidly. This technique, known as "living-off-the-land" (LotL), allows attackers to manipulate the software’s native functionalities for remote access, file transfers, and command execution, effectively blending into legitimate system activity.


For continuous updates and more in-depth coverage of this unfolding situation in software security, follow us on Twitter and LinkedIn.

spot_img

Related articles

Recent articles

Dubai Airshow 2025: The Biggest Yet, Showcasing eVTOL Innovations, a Mega Space Pavilion, and 1,500 Exhibitors

Dubai Airshow 2025: The Biggest Innovation Showcase Yet Overview of Dubai Airshow 2025 The Dubai Airshow 2025 is gearing up to take place at Dubai World...

Mohali Court Denies Bail to Main Suspect in ₹72-Lakh Cyber Fraud Case

Mohali Court Denies Bail in ₹72-Lakh Cyber Fraud Case A Mohali court has declined a regular bail request from Arun, a 23-year-old man involved in...

Railways Shuts Down 7.7 Million Accounts in Major Tatkal Bot Fraud Crackdown

Indian Railways: Strengthening Digital Security for Ticket Bookings In a significant move to combat ticket fraud, Indian Railways has rolled out a new security regimen...

Discover Six Flags Qiddiya: Opening Date, Ticket Prices, and 28 Record-Breaking Rides

Discovering Qiddiya City: A New Era of Entertainment An Overview of Qiddiya City Nestled in the stunning Tuwaiq Mountains and just a 40-minute drive from Riyadh,...