ConnectWise has fixed critical flaws in its Automate remote-management platform that could enable AiTM update attacks. The ConnectWise Automate bug allowing AiTM update attacks exposed managed service providers and enterprises to risks of malicious updates and network compromise. The company responded quickly to strengthen encryption, authentication, and package validation.


Details of the Vulnerabilities

Researchers discovered two interconnected flaws that created an attack path. The first, CVE-2025-11492, allowed Automate agents to use unencrypted HTTP connections instead of HTTPS. Attackers could exploit this to intercept and manipulate communication between endpoints.

The second, CVE-2025-11493, lacked proper integrity verification for update files. Without this safeguard, attackers could disguise malicious software as legitimate patches. When combined, the flaws gave adversaries full control to deliver fake updates through a trusted channel.


Impact on Users

ConnectWise Automate manages thousands of systems across enterprise and MSP environments. Attackers exploiting these issues could seize administrator privileges, install backdoors, and move laterally across networks.

Security analysts noted that this scenario represents a typical supply-chain risk: attackers weaponize trusted tools to distribute malware at scale. Each compromised server could jeopardize hundreds of connected machines.


ConnectWise’s Response

ConnectWise addressed both flaws in Automate version 2025.9. Cloud deployments received automatic updates, while on-premises users had to apply patches manually.

The company advised administrators to enforce HTTPS, disable HTTP fallback options, and verify that all update packages carry valid digital signatures. ConnectWise also encouraged IT teams to monitor network logs for unusual activity that could signal prior exploitation.

No active exploitation has been detected so far, but the company warned that unpatched systems remain vulnerable.


Lessons for Remote-Management Security

This case highlights why encryption and signature verification are essential for remote-management tools. These systems handle privileged access, making them valuable targets for attackers.

Security teams should treat management platforms like critical assets. Continuous patching, network segmentation, and zero-trust access policies reduce the risk of similar breaches.


Conclusion

The ConnectWise Automate bug allowing AiTM update attacks demonstrates how attackers can exploit overlooked configuration gaps to compromise entire networks. ConnectWise acted swiftly to contain the threat, but long-term protection depends on user vigilance. By applying patches promptly and validating every update, organizations can prevent malicious actors from turning essential management tools into attack vectors.


0 responses to “ConnectWise Fixes Automate Bug Allowing AiTM Update Attacks”