Certificate Signing Extension Returns Encrypted Values
Vulnerability Description
In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an encrypted representation could be exposed in client responses. Updating the Certificate Signing Extension to version 1.0.12 or higher ensures configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14823
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Michael Gilliam (Dean Dorton Allen Ford, PLLC)
More from ConnectWise
View All →Affected Vendor
ConnectWise
View all reports →