Sécurité et conformité

DEVO-2022-0012

Résumé

The MSI installers for Devolutions Server Console and Remote Desktop Manager were vulnerable to a local privilege escalation.

This issue is caused by a vulnerability in the Advanced Installer product.The following Advanced Installer release fixes this issue :https://www.advancedinstaller.com/release-20.1.html

Produits affectés

Devolutions Server Console 2022.3.4 and earlier

Remote Desktop Manager 2022.3.23 and earlier

Journal des modifications

Initial Publication - 2022-11-25

Sévérité

High

Produit

Remote Desktop Manager, Devolutions Server Console

Version corrigée

RDM 2022.3.24, DVLS Console 2022.3.5

Local privilege escalation in RDM and DVLS installers.

Description

The version of Advanced Installer used to generate Remote Desktop Manager and Devolutions Server MSI installer files was vulnerable to a privilege escalation.

Mesures correctives et solutions de contournement

Upgrade to Devolutions Server Console to 2022.3.5 and higher

Upgrade to Remote Desktop Manager to 2022.3.24 and higher

Sévérité

High - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Produits affectés

Devolutions Server Console 2022.3.4 and earlier

Remote Desktop Manager 2022.3.23 and earlier

CVE(s)

CVE-2023-25396

Crédits

Jean-Luca Gruber

Devolutions aide les organisations à contrôler le chaos relié aux TI en offrant des solutions sécurisées de gestion d’accès privilégiés, de connexions à distance et de mots de passe.

DEVOLUTIONS

Légal & vie privée | infos@devolutions.net

Tous droits réservés © 2025 Devolutions