Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
History

Wed, 26 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 17:30:00 +0000

Type Values Removed Values Added
Description Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
Weaknesses CWE-284
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2025-03-26T17:14:59.457Z

Updated: 2025-03-26T19:31:19.517Z

Reserved: 2025-03-18T14:03:06.856Z

Link: CVE-2025-2499

cve-icon Vulnrichment

Updated: 2025-03-26T19:31:14.565Z

cve-icon NVD

Status : Received

Published: 2025-03-26T18:15:25.720

Modified: 2025-03-26T20:15:22.687

Link: CVE-2025-2499

cve-icon Redhat

No data.