Security & Compliance
DEVO-2023-0015
Summary
Remote Desktop Manager Windows is affected by multiple security vulnerabilities.
Affected Products
Remote Desktop Manager Windows
Change Log
Initial Publication - 2023-08-21
Severity
Medium
Product
Remote Desktop Manager Windows
Fix Version
2023.2.22
Unauthorized Connection Exploit via Remote Tools in Remote Desktop Manager
Description
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.
Remediation and Workarounds
Upgrade to Remote Desktop Manager Windows 2023.2.22 and higher.
Severity
Medium - 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products
Remote Desktop Manager Windows 2023.2.19 and earlier.
CVE(s)
CVE-2023-4373
Incorrect vault used for the duplicate entry feature.
Description
Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.
Remediation and Workarounds
Upgrade to Remote Desktop Manager Windows 2023.2.22 and higher.
Severity
Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N 5.7
Affected Products
Remote Desktop Manager Windows 2023.2.19 and earlier.
CVE(s)
CVE-2023-4417