Security & Compliance

DEVO-2022-0011

Summary

Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malicious user to access the application.

Affected Products

Remote Desktop Manager 2022.3.26 and earlier.

Change Log

Initial Publication - 2022-12-20

Severity

High

Product

Remote Desktop Manager

Fix Version

2022.3.27

Local application lock bypass

Description

Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malicious user to access the application.

Remediation and Workarounds

Upgrade to Remote Desktop Manager 2022.3.27 and later.

Severity

High - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

Remote Desktop Manager 2022.3.26 and earlier.

CVE(s)

CVE-2022-4287