
Writeup and code for CVE-2025-11492, CVE-2025-11493 - RCE in ConnctWise Automate RMM via Adversary-in-the-Middle
As part of a Pentation Test, I discovered multiple vulnerabilities in the ConnectWise Automate Remote Monitoring and Management (RMM) agent. ConnectWise is used by many Managed Service Providers (MSPs) to manage and monitor client devices. These vulnerabilities enabled remote code execution if an attacker could establish network Adversary-in-the-Middle, or could be used as local privilege escalation and stealthy persistence if an attacker obtained code execution or physical access to a device running the ConnectWise Automate agent.
The vulnerabilities were reported to ConnectWise on 20 August 2025. ConnectWise assigned CVE IDs and released a patch in version 2025.9 on 16 October 2025.
ConnectWise Bulletin:
CVE IDs:
2025.9 and publish security bulletin and CVEs.I appreciated ConnectWise's swift responses and their collaborative approach to remediation and willingness to engage in discussion on how best to approach classification, and remediation.
Classifying these vulnerabilities was an interesting challenge. While switching to HTTPs resolves practically all of the scenarios in this report, it was evident that this was originally a design choice (to support HTTP) to improve reliability of agent-server communication. The encryption scheme seemed to partially acknowledge/attempt to mitigate the risk of AiTM, but was not applied consistently. Digging into this involved trying to classify whether the weakness was http itself or the lack of encryption on-top of HTTP as well as replay prevention, plugin validation, etc. were all their own vulnerabilities. At one point ConnectWise was considering 5+ separate CVEs for different aspects of the vulnerabilities.
Additionally, the scope and attack vector changed depending on whether the vulnerability was considered from an AiTM e.g. coffee shop Wi-Fi or LPE/physical access perspective. An alternate approach would be to consider each scenario as a separate vulnerability, e.g. AiTM RCE, LPE, Persistence takeover, etc.
A final learning is that even in 2025, we still struggle to share files effectively :D (email security did not like me emailing .dll files or .zips containing them).
This report is being published following ConnectWise's release of a patch and disclosure of the CVEs, and with their agreement that such disclosure does not harm their users. Furthermore, I believe that public disclosure of these vulnerabilities and their mitigations will help other vendors and security professionals better understand and mitigate risks in both ConnectWise Automate, and other RMM systems.
The content is intended for lawful, authorized security research and educational purposes only. Unauthorized use of this information to compromise systems, networks, or data is illegal and unethical. The content is provided as-is and without warranties of any kind. The author(s) disclaim all liability for any damages resulting from the use or misuse of this information.
If using this code or information for further research, practice responsible disclosure by reporting any discovered vulnerabilities to the affected vendor(s).
As well as the report below, this repository contains PoC code to demonstrate the vulnerabilities. See automate_server/README.md for details on the fake server implementation and usage instructions.
This code could also be used to perform further (ethical) security research on ConnectWise Automate.
The following report (or a version close to it), and PoC python code in this repository, was provided to ConnectWise, along with recommended mitigations.
The removed mitigations section goes into more detail on changes that could be made to the Automate agent to harden it in several ways against these vulnerabilities.
As some of these changes are still under consideration by ConnectWise, that section has been removed from this public disclosure.
The ConnectWise Automate Remote Monitoring and Management (RMM) agent (tested on latest version as of August 2025, version string 250.252) is vulnerable to network-based Remote Code Execution in certain configurations. If the agent is configured to use an unencrypted HTTP transport (either primarily or as a fallback) for its Server Address and an attacker can perform a adversary-in-the-middle (AiTM) attack, then they can remotely execute code as SYSTEM. This configuration has been observed in the wild from multiple Managed Service Providers (MSPs).
Exploitation is also possible if the attacker gains physical access to the device as a non-admin or can otherwise connect the device to an attacker‑controlled network (i.e. the vulnerability can be used as a Local Privilege Escalation). Although Automate employs an encryption system to encrypt and validate most RMM commands, its plugin system lacks adequate protection and remains susceptible to Remote Code Execution.
By implementing a custom server mimicking Automate's control server, the Automate agent can be coerced into downloading and executing a malicious plugin.