CVE-2025-3935
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-3935 reveals that ScreenConnect versions 25.2.3 and older are vulnerable to ViewState code injection attacks. ASP.NET Web Forms utilize ViewState to maintain page and control states, and these states are encoded using Base64 and protected by machine keys. However, obtaining these machine keys requires privileged system access. If an attacker manages to steal these keys, they could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. Notably, this vulnerability stems from a platform-level behavior rather than a ScreenConnect flaw, and the 2025.4 patch disables ViewState and eliminates its dependency.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ConnectWise ScreenConnect
Affected Vendors
- ConnectWise