PT-2025-23168 · Devolutions · Devolutions Remote Desktop Manager
Published
2025-05-29
·
Updated
2025-07-02
·
CVE-2025-5334
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Devolutions Remote Desktop Manager versions 2025.1.34.0 and earlier
Description
The issue allows an authenticated user to gain unauthorized access to private personal information in the user vaults component. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.
Recommendations
For Devolutions Remote Desktop Manager versions 2025.1.34.0 and earlier, update to a version that contains a fix for this issue to prevent unauthorized access to private personal information. As a temporary workaround, consider restricting access to the user vaults component to minimize the risk of exploitation. Avoid editing entries in user vaults until the issue is resolved to prevent unintentional movement of entries to shared vaults.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Devolutions Remote Desktop Manager