ScreenConnect 25.8 Security Patch
Date: 12/11/2025
Products: ScreenConnect
Severity: Important
Priority: 2 – Moderate
Summary
ConnectWise has released a security update for ScreenConnect™ that addresses issues which could allow unauthorized access to configuration data or the installation of untrusted extensions under specific conditions. There is no evidence of exploitation, and these issues require authorized or administrative-level access to be leveraged. These issues affect only the ScreenConnect server component; host and guest clients are not impacted. The ScreenConnect 25.8 patch strengthens server-side validation, enforces integrity checks for extension installations, and enhances overall platform security and stability.
The ScreenConnect 25.8 patch strengthens server-side validation, enforces integrity checks for extension installations, and enhances overall platform security and stability.
Vulnerability
CVE-2025-14265
| CWE ID | Description | Base Score | Vector |
|---|---|---|---|
| CWE-494 | Download of Code Without Integrity Check |
9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Severity
Important — Vulnerabilities that could compromise confidential data or other resources but require additional access, privilege or circumstances to do so.
Priority
2 – Moderate — Vulnerabilities that have elevated risk but exploits are neither known nor anticipated to be imminent. Recommend updates be prioritized against normal change management timelines but no longer than 30 days.
Affected Versions
ScreenConnect versions prior to 25.8 are impacted.
Remediation
Cloud
No action is required. ScreenConnect servers hosted in “screenconnect.com” cloud (standalone and Automate/RMM integrated) or “hostedrmm.com” for Automate partners have been updated to remediate the issue.
On-prem
ScreenConnect Partners:
Please upgrade to ScreenConnect version 25.8 and update your guest clients to the same version. Visit Download | ScreenConnect page to download and apply the update (access requires a valid on-premises license).
- If your license is out of maintenance, you must upgrade your license before installing the latest supported release of ScreenConnect.
- For instructions on updating to the newest release, please reference this doc: Upgrade an on-premise installation - ConnectWise
Automate On-Prem Partners with ScreenConnect Integration:
For partners using an on-premises ScreenConnect installation integrated with Automate, please follow these steps to ensure a smooth upgrade to ScreenConnect 25.8:
- If applicable, confirm that the Automate ScreenConnect Extension is updated to version 4.4.0.16.
- If the extension is not yet at 4.4.0.16, allow it to auto-update or apply the update from the Extensions tab.
- Once the extension is confirmed to be on 4.4.0.16, you may safely upgrade the ScreenConnect server to version 25.8. Visit the Automate Product Updates page to download and apply the ScreenConnect 25.8 update