MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2022-0005

An arbitrary file write in entry attachments was fixed in Remote Desktop Manager 2022.2

Affected Products

Remote Desktop Manager
2022.1 and earlier

Change Log

Initial Publication - 2022-06-21

Arbitrary file write via path traversal in entry attachments

Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Files can be attached to entries in Remote Desktop Manager. Special path characters were not being properly sanitized when constructing the destination path. An attacker could construct a path to write the file in an arbitrary directory when the file is opened.

CVE(s)

CVE-2022-33995

Remediation and Workarounds

Upgrade to Remote Desktop Manager 2022.2