CVE-2025-14823: Certificate Signing Extension Returns Encrypted Values
In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an encrypted representation could be exposed in client responses. Updating the Certificate Signing Extension to version 1.0.12 or higher ensures configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14823?
CVE-2025-14823 has been rated as a high-severity vulnerability due to the potential exposure of sensitive encrypted configuration values to unauthenticated users.
How do I fix CVE-2025-14823?
To fix CVE-2025-14823, you should update the ScreenConnect Certificate Signing Extension to version 1.0.12 or later.
What are the risks associated with CVE-2025-14823?
The risks associated with CVE-2025-14823 include unauthorized access to sensitive data, potentially leading to further exploitation of the system.
Who is affected by CVE-2025-14823?
CVE-2025-14823 affects users of the ScreenConnect Certificate Signing Extension versions prior to 1.0.12.
Can CVE-2025-14823 be exploited remotely?
Yes, CVE-2025-14823 can be exploited remotely as it involves a client-facing endpoint that may expose sensitive information.