
CISA Adds Microsoft Windows Shell and ConnectWise ScreenConnect Vulnerabilities to Known Exploited Vulnerabilities Catalog
Breaking NewsHackingSecurityCISAhacking newsinformation security newsIT Information SecurityKnown Exploited Vulnerabilities CatalogPierluigi PaganiniSecurity AffairsSecurity News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: one affecting Microsoft Windows Shell and another in ConnectWise ScreenConnect. The specific flaw identified for ConnectWise ScreenConnect is tracked as CVE-2024-0221, described as a path traversal vulnerability. No additional technical details, exploitation dates, or impact assessments were provided in the notice. The inclusion in the KEV catalog indicates active exploitation of these vulnerabilities in the wild. The action was reported by Security Affairs without further contextual data on affected versions or attack vectors.