CVE-2025-3935
CVE-2025-3935 is a high-severity vulnerability in Connectwise Screenconnect with a CVSS 3.x base score of 8.1. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2025-06-02). The underlying weakness is classified as CWE-502.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- EPSS exploit prediction: 4% (89th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2025-06-02)
- EU (EUVD) id: EUVD-2025-12502
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2025-06-02)
- Weakness: CWE-502
- Affected product: Connectwise Screenconnect
- Published:
- Last modified:
Description
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior. This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.
Frequently asked questions
- What is CVE-2025-3935?
- ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior. This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.
- How severe is CVE-2025-3935?
- CVE-2025-3935 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-3935 being actively exploited?
- Yes. CVE-2025-3935 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2025-06-02, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2025-3935?
- CVE-2025-3935 affects Connectwise Screenconnect. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-3935?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2025-3935 have an EU (EUVD) identifier?
- Yes. CVE-2025-3935 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-12502. It is also flagged as exploited in the EUVD (since 2025-06-02).
- When was CVE-2025-3935 published?
- CVE-2025-3935 was published on 2025-04-25 and last updated on 2026-06-17.
References
- https://www.connectwise.com/company/trust/advisories
- https://www.connectwise.com/company/trust/security-bulletins/screenconnect-security-patch-2025.4
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3935
Affected products (1)
- cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*
More vulnerabilities in Connectwise Screenconnect
- CVE-2024-1709 — Critical (CVSS 10.0): ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or…
- CVE-2026-84869 — Critical (CVSS 9.9): A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session…
- CVE-2025-14265 — Critical (CVSS 9.1): In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension…
- CVE-2024-1708 — High (CVSS 8.4): ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker…
- CVE-2023-47257 — High (CVSS 8.1): ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via…
- CVE-2023-47256 — Medium (CVSS 5.5): ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of…
All CVEs affecting Connectwise Screenconnect →
Other CWE-502 (Deserialization of Untrusted Data) vulnerabilities
- CVE-2026-70416 — Critical (CVSS 10.0): Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An…
- CVE-2026-82222 — Critical (CVSS 10.0): Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue…
- CVE-2026-69836 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release…
- CVE-2026-11756 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…
- CVE-2026-41104 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose…
Browse all CWE-502 (Deserialization of Untrusted Data) vulnerabilities →