CVE-2025-14823 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returne…
Medium CVSS: 5.3

CVE-2025-14823

In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an encrypted representation could be exposed in client responses. Updating the Certificate Signing Extension to version 1.0.12 or higher ensures configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.
Vendor
Connectwise
Product
Screenconnect
CWE
CWE-201
Yayın Tarihi
2025-12-18 16:15:52
Güncelleme
2026-01-16 19:10:48
Source Identifier
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
KEV Date Added
-

Kategoriler

Referanslar