CVE-2025-3935

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 287

Summary

CVE-2025-3935 reveals that ScreenConnect versions 25.2.3 and older are vulnerable to ViewState code injection attacks. ASP.NET Web Forms utilize ViewState to maintain page and control states, and these states are encoded using Base64 and protected by machine keys. However, obtaining these machine keys requires privileged system access. If an attacker manages to steal these keys, they could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. Notably, this vulnerability stems from a platform-level behavior rather than a ScreenConnect flaw, and the 2025.4 patch disables ViewState and eliminates its dependency.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • ConnectWise ScreenConnect

Affected Vendors

  • ConnectWise