CVE-2025-2600
26.03.2025, 18:15
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.Enginsight
| Vendor | Product | Version |
|---|---|---|
| devolutions | remote_desktop_manager | 𝑥 < 2024.3.31.0 |
| devolutions | remote_desktop_manager | 𝑥 < 2024.3.31.0 |
| devolutions | remote_desktop_manager | 2025.1.24.0 ≤ 𝑥 < 2025.1.26.0 |
| devolutions | remote_desktop_manager | 2025.1.24.0 ≤ 𝑥 < 2025.1.26.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration