CVE-2024-1708 - ScreenConnect Path Traversal Exploitation — Detection Rule

This detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708.

Read the full analysis on IntelFusions