CVE-2024-1708 - ScreenConnect Path Traversal Exploitation
Description
This detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708.
Query · sigma
selection: Image|endswith: \ScreenConnect.Service.exe TargetFilename|endswith: - ScreenConnect\\App_Extensions\\*.ashx - ScreenConnect\\App_Extensions\\*.aspx filter_main_legit_extension: TargetFilename|contains: ScreenConnect\App_Extensions\\*\\ condition: selection and not 1 of filter_main_*
Known false positives
- This will occur legitimately as well and will result in some benign activity.