Sécurité et conformité
DEVO-2022-0010
Résumé
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.
Produits affectés
Remote Desktop Manager 2022.3.13 to 2022.3.24.
Journal des modifications
Initial publication - 2022-12-7
Sévérité
Medium
Produit
Remote Desktop Manager
Version corrigée
2022.3.26
Remote Desktop Manager Azure SQL privilege escalation
Description
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.
Mesures correctives et solutions de contournement
Update to Remote Desktop Manager 2022.3.26 or higher.
Sévérité
High - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Produits affectés
Remote Desktop Manager 2022.3.13 to 2022.3.24
CVE(s)
CVE-2022-3641