← Back to CVE List
Vulnerability Analysis
ScreenConnect Exposure to ASP.NET ViewState Code Injection

CVE-2025-3935

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server.  The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior.  This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.

CISA KEV
CVSS Base Score
8.1
HIGH
Exploitability:2.3
Impact Score:5.9
Temporal Score:-
EPSS:3.35%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2025-06-02
Ransomware Use
Unknown
KEV Due Date
2025-06-23
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
3.348%
EPSS Percentile
87.1th pct
GitHub Severity
HIGH
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD