---
id: CVE-2025-14265
title: >-
  In versions of ScreenConnect™ prior to 25.8, server-side validation and
  integrity checks within the extension subsystem could allow the installation
  and execution of untrusted or arbitrary extensions by authorized or
  administrative users…
summary: >-
  In versions of ScreenConnect™ prior to 25.8, server-side validation and
  integrity checks within the extension subsystem could allow the installation
  and execution of untrusted or arbitrary extensions by authorized or
  administrative users…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-494
vendor: connectwise
product: screenconnect
affected:
  - screenconnect < 25.8.0.9438
patched:
  - screenconnect 25.8.0.9438
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14265'
references:
  - url: >-
      https://www.connectwise.com/company/trust/security-bulletins/screenconnect-2025.8-security-patch
    label: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
tags:
  - nvd
epss: 0.00368
epssPercentile: 0.28504
ingestedAt: '2026-10-07T20:46:46.850Z'
---

## Overview

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.

## Affected

- `screenconnect < 25.8.0.9438`

## Remediation

Upgrade past the affected range:

- `screenconnect 25.8.0.9438`
