Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2024-0016 |
|
History
Fri, 28 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions remote Desktop Manager |
|
| CPEs | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:* |
|
| Vendors & Products |
Devolutions
Devolutions remote Desktop Manager |
Mon, 25 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 25 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature. | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2024-11-25T14:46:20.186Z
Updated: 2024-11-25T16:47:53.171Z
Reserved: 2024-11-25T14:35:25.709Z
Link: CVE-2024-11672
Updated: 2024-11-25T16:47:49.150Z
Status : Analyzed
Published: 2024-11-25T15:15:07.180
Modified: 2025-03-28T16:21:52.263
Link: CVE-2024-11672
No data.