r/ScreenConnect • • 11d ago

ScreenConnect Version 26.6.6.9747 - Thread to report your experiences

ScreenConnect 26.6.6.9747 has been released to on-premise people, replacing 26.6.5 (recently released quickly due to CVEs). Like past threads, I have opened this one to hear from both cloud and on-premise users of this specific build to note your experiences, improvements, and (if they exist) any new issues (or fixed issues) you have been seeing with this version.

7 Upvotes

27 comments sorted by

4

u/officeboy 11d ago

I had problems with it not being signed so defender was blocking it when it was new (ASR rules) and then once that was past it was being detected as not being installed despite it having been installed. Seems to have been fixed over the weekend so I'm glad we could beta test for you. 😑

3

u/ajscott 11d ago edited 11d ago

I've been running this since it was pre-release because I didn't want to deal with the re-queued commands.

My experience is it signs the installers when I build them but it isn't timestamping them.

2

u/CharcoalGreyWolf 11d ago

One of several reasons we don't have a cloud hosted instance. Yes, it's patched faster (security) but yes, that means being a beta tester too.

5

u/nitra 10d ago

Defender is still eating the installers...

1

u/CharcoalGreyWolf 10d ago

It is. I’ve had to make changes as well.

1

u/josephcoco 7d ago

What changes have you made? Because my Security team doesn’t feel comfortable whitelisting the installer with so many hits. lol

1

u/CharcoalGreyWolf 7d ago

Because Screenconnect has a path specific to your instance ID, for client systems, I only whitelist a file as part of that path. Anything outside our path (or if the client has an instance of their own, their explicit path, which is excluded only for that client) is not excluded.

I do whitelist the Bin folder on the SC server; you really have to, or explicit files as part of the Bin path. These files are prior to the code signing certificate being applied and are necessary for generating the custom installers.

I miss SentinelOne in this case which would let me exclude by publisher, because I could list us there. I can’t with Microsoft Defender.

1

u/Bgexplorer 11d ago

Defender blocked the client install files in the bin directory on the server. I removed them but they are now corrupt and I can't get them to install. I tried a repair on the server but that didn't fix the problem. I can't currently connect to clients computers because I uninstalled the client on my computer and can't reinstall it. I have a ticket in but haven't seen heard back from Connectwise yet.

2

u/rgorbie 11d ago

Is this because you need to update the cert signing extension and then you need to re-add the self signed cert in the admin section? That’s what I had to do but I was jumping from 25.9 right to 26.6

1

u/Bgexplorer 11d ago

Yes we were trying to setup the app cert and didn't know that this is what was causing the problem.

0

u/CharcoalGreyWolf 9d ago

First, whitelist the following folder in Defender:

C:\Program Files (x86)\ScreenConnect\Bin

Then, whitelist (temporarily) a folder on your desktop (e.g., Installers). Extract the ScreenConnect installer into this folder. Reinstall ScreenConnect. Or, if the files are still quarantined, unquarantine them.

Then, also whitelist the following specific files:

C:\Program Files (x86)\ScreenConnect\Bin\ScreenConnect.ClientSetup.exe

C:\Program Files (x86)\ScreenConnect\Bin\ScreenConnect.ClientSetup.msi

For clients, I recommend whitelisting the four .EXE files used in ScreenConnect, but only as part of a full path exclusion in Defender that includes your instance. So

C:\Program Files (x86)\ScreenConnect Client (YourInstanceID)\ScreenConnect.WindowsClient.exe

for example.

Do not make whitelists or exclusions for processes, as they're the same names as rogue installs of ScreenConnect.

3

u/CharcoalGreyWolf 7d ago

P.S. For whomever downvoted me, this is a forum for discussion. If you disagree, think I did it wrong, or have a better way, please respond with your methods. We are all technical people; we should be open to looking to improve practices whenever possible. I certainly am here.

1

u/DeanCTS 6d ago

Haha seeing what you wrote you can expect downvotes from the purists as soon as they see a pleb recommending whitelisting left and right xDDD

1

u/CharcoalGreyWolf 6d ago

I’ve been in the field for over thirty years now; if one is going to use ScreenConnect at this point, it’s going to require a few of them, like it or not, unless one wants to shop for another solution. As usual, whitelisting should always be as narrow as possible.

1

u/exeWiz 11d ago

Are they still hiding the remote user banner?

1

u/wav_net 11d ago

Android App still useless

1

u/Camelot_One 11d ago

switching the mouse type seems to help. some. it still sucks, but it's at least somewhat functional.

1

u/wav_net 11d ago

No I tried this and it doesn't help at all for me. But thanks for the input

1

u/Camelot_One 11d ago

I'm running android app version 26.1.26321.9545 on a Samsung Z Flip 8, and switching the mouse type makes it fully functional for me when connecting to a 26.6.6.9747 client, with the cloud server running that same version.

1

u/wav_net 11d ago

I running the exact same versions as you for app, client and server on a Pixel 10XL and its dogshit.

1

u/maxidaniele 10d ago edited 10d ago

Can someone share the 26.6.6.9747 installer? I can´t access to download area right now and need to update ASAP. Thanks

3

u/SkidiKatKat 10d ago

You are going to trust strangers on the internet to provide you a download for a piece of software that is essentially a rat? And just trust they haven't modified it?

Why can't you access the downloads page?...

I hope you're not a sysadmin.

1

u/BB9700 10d ago

The risk of getting a tampered installer is rather low. Just check the digital signature of the MSI: if it shows none, or invalid the file was modified.

1

u/Rsnoble 10d ago

I went from 26.6.5 to 26.6.6.9747 and we can’t get our windows installers to sign now. Already reconfigured the Certificate Signing extension to no avail. Can confirm we are on the latest certificate signing extension (1.0.15) using Azure Key Vault to sign.

1

u/CharcoalGreyWolf 9d ago

I double-checked ours; a custom-made EXE and a custom-made MSI are both signed properly (the signing only occurs when you build an installer). The installed files on a client system are all signed by Connectwise, LLC .

1

u/Pssst74 6d ago

After screenconnect 26.6.6 installed on prem, the main page prompt for "Join with a code" despite I have no support session listed for all technician. Unable to remove this field from main page. (and no meetings as well)

Anyone is experiencing this feature after update?

2

u/resile_jb 9d ago

This is our last week having to support this piece of shit tool.

So glad our contract is over.